ZYVOPMulti-Platform Sync
SeriesAI NewsWhy ZyVOPJoin Discord
LoginGet Started
ZYVOPMulti-Platform Sync

The Developer Publishing Hub. Write once, publish everywhere, and make your work citation-ready with built-in SEO, AEO, and GEO discovery support. Zero reader paywalls.

Content

  • Categories
  • Tags
  • Badges
  • Leaderboard
  • Write Article
  • Newsletter

Company

  • About Us
  • Why ZyVOP
  • Developer API & CLI
  • Write for Us
  • Contact

Connect

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DMCA Policy
  • Code of Conduct

© 2026 ZyVOP. Developer Publishing Hub.

Zero paywalls · Full content ownership
All systems operational
HomeThe Hidden Risks of PHP Object Unserialization and How to Avoid Them

The Hidden Risks of PHP Object Unserialization and How to Avoid Them

Denzyl
Denzyl
Senior Developer
September 6, 2026
3 min read
The Hidden Risks of PHP Object Unserialization and How to Avoid Them
#php#laravel#webdev#beginners

Serializing in PHP is a way of converting a PHP object into a string. This string can be used in various ways, such as storing it in a database or passing it to another function. The PHP documentation says this is handy when passing PHP values around without losing their type and structure. But I have never had that problem before. Maybe I’m not seeing it.

<?php$test = new User();$test->name = "Denzyl";echo serialize($test);/// Output: O:4:"User":1:{s:4:"name";s:6:"Denzyl";}

Enter fullscreen mode Exit fullscreen mode

So, let's digest the string. The o stands for Object, and the following number is the length of the object's name. The two letters s stand for string and the length of the string's name.

When you need to convert the string back into PHP, call the unserialize function and pass the string as a parameter.

When serializing an object, two methods are automagically being called. __serialize() & __sleep(). This will allow the class author to do something before converting the object into a string.
That is straight to the point. But for now, let’s focus on unserializing the string. This means converting the string into a real PHP object that can be later used at runtime in your PHP code.

<?php

$string = 'O:8:"User":1:{s:4:"name";s:6:"Denzyl";}';echo unserialize($string)->name;/// Output: Denzyl

Enter fullscreen mode Exit fullscreen mode

The same functionalities also apply to unserializing. But this time, the two methods are __unserialize() and __wakeup().

But why is it a bad idea?

Using unserialize without knowing it can lead to remote code execution. That's why they say never to trust input.
Let's say you are lazy and you trust a random input, and you concatenate to the serialized object so you can
change a value inside the object. BOOM, you can be hacked.

<?php$username = $_GET['username'];$serialized = 'O:8:"User":1:{s:4:"name";s:6:"' . $username . '";}';

Enter fullscreen mode Exit fullscreen mode

I won't explain how to write an exploit for something like this. Some tools can automatically generate a payload for you, and you can call yourself a script kiddie(we all start somewhere). The one I know is PHPGGC.

To understand the exploit, you can read the OWASP article.
If you didn't know this before, also read the rest of the OWASP articles about vulnerabilities

I know I haven't explained how to write an exploit. I don't think I can do a better job than the articles on the internet. But now you know this, and you can do your research.

How to prevent being exploited?

Why would you want to use this? I do not know; I haven't been programming long enough(~15 years) to have the opportunity to solve a problem using serialize/unserialize.
My solution is too drastic. The simple answer is. Don't use it in my PHP projects.

This article is part of a series of articles in my journey of writing a static analysis tool for PHP that can scan massive projects in a couple of minutes/seconds. And look for rules
that the developers want to have in their projects. At the time of writing this article, I'm working on a rule to stop
people from using unserialize, and it should be ready for the next release. Follow the project so that you will get notified when
I decided to write even more rules.

💡 TL;DR & Key Takeaways:
**TL;DR**
PHP serialization converts objects to strings (e.g., `O:4:"User":1:{s:4:"name";s:6:"Denzyl";}`) and back with `unserialize()`, invoking magic methods (`__serialize`/`__sleep` and `__unserialize`/`__wakeup`). However, unserializing unchecked data can enable remote code execution, so never trust external input.

- The serialized format encodes type, class name length, property names, and values, allowing lossless storage or transmission of PHP objects.
- Magic methods (`__serialize`, `__sleep`, `__unserialize`, `__wakeup`) let classes customize preprocessing and post‑processing during (un)serialization.
- Injecting user‑controlled data into a serialized string creates a severe security vulnerability; always validate or avoid `unserialize()` on untrusted sources.

Comments (0)

Login to post a comment.

Denzyl
Denzyl

Passionate developer sharing knowledge about modern web technologies and best practices.

Subscribe to Denzyl's Newsletter

Direct email dispatches when new stories are published. Zero algorithms.

More from Denzyl

View profile

Finding Duplicates Across Years: A DIY Workflow for Cleaning 300 GB of Photos

Finding "Duplicates Through Time": How I Cleaned Up 300GB of Photos Without Losing...

3 minSep 6

Building Siegu: A Rust‑Powered, Local‑First Photo Library with Tauri

I can't remember exactly when I started using Google Photos, but it’s been my go-to for a long time,...

5 minSep 6

From Throw-and-Pray to Predictable: Introducing Box, a Rust‑Inspired Result Type for PHP 8.1+

Most PHP developers are stuck in a cycle of "throw-and-pray" error handling. You write a method, it...

2 minSep 6

Making GitHub CI Logs Readable: Structured Output with Phanalist

Have you ever been in a situation where you made a PR or MR and waited for a couple of seconds for...

3 minSep 6

How I made it impossible to write spaghetti code. Part 2

This is the part(3) of a series. I suggest you read parts 1 and 2 before this one. In part 2, I...

3 minSep 6