-
Notifications
You must be signed in to change notification settings - Fork 0
serialToArray
Corey Avis edited this page Sep 23, 2026
·
2 revisions
Safely converts a serialized string back into a native PHP array while preventing Object Injection attacks.
serialToArray(string $serial): array
serial (string) : The serialized string to decode.
(array)
: Returns the decoded array on success.
: Returns an empty array ([]) if the string is malformed, corrupted, or decodes into a non-array scalar value.
📌 Disables PHP class instantiation to prevent PHP Object Injection vulnerabilities, returning a safe
[]fallback while logging a warning on failure.
$cphp->serialToArray('a:3:{s:2:"id";i:10;s:4:"user";s:4:"name";s:6:"active";b:1;}');
// Result: ['id' => 10, 'user' => 'name', 'active' => true]
$cphp->serialToArray('a:invalid');
// Result: [] (Logs a warning)
- Triggers a warning if there was an issue deserializing the string.
arrayToSerial | serialToJson | serialToObject
Home | CoreyPHP | Conversion