PlugMyPlugin
← Browse

php-unserialize-audit

califio ★ 62

This plugin audits PHP deserialization endpoints (unserialize, session decoders, WDDX, phar metadata, and custom handlers) for memory safety vulnerabilities including use-after-free, type confusion, and heap overflows. It analyzes PHP engine internals to detect partial-object __destruct issues, signed-length overflows, and parse inconsistencies that could enable exploitation.

Security Code Review No API key detected prompt pack

Install

> /plugin marketplace add califio/skills/tree/HEAD/plugins/php-unserialize-audit
> /plugin install php-unserialize-audit

Source: https://github.com/califio/skills/tree/HEAD/plugins/php-unserialize-audit

What it's made of

1 command · 1 skill

Commands
1
Agents
0
Skills
1
MCP servers
0
Hooks
0

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
none
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (califio).