.PHAR

PHAR File

PHP Archive
Ask a question
QUICK ANSWER

A PHAR file is a PHP Archive - a complete PHP application or library packaged into one executable file, the PHP equivalent of a Java JAR. To run it, open a terminal with PHP installed and type php tool.phar. Because it contains runnable code, only execute PHAR files from trusted, official sources.

Developer: Greg Beaver / PHP project (PEAR) Category: Executable Files Open standard MIME: application/x-php-archive
OPENS ON Windows macOS Linux
Related: .APK · .EXE · .VBS · .JAR

On this page

19k+ extensions indexed
Last reviewed Aug 17, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the PHAR file format?

.phar files are associated with the PHP development environment. A .phar archive is the PHP equivalent of a JAR file - it packages an entire PHP application or library into a single self-contained, executable bundle that can be distributed as one file.

What kind of data can PHAR files contain?

.phar archives store PHP scripts and any supporting assets (templates, configs, resources), optionally compressed with gzip or bzip2 on a per-file or whole-archive basis. Every .phar file contains an executable PHP stub, a binary manifest listing the bundled files with metadata, and an optional cryptographic signature (MD5, SHA-1, SHA-256, SHA-512, or OpenSSL) verified via phar.require_hash.

How can I run PHAR files?

.phar files can be run directly with the PHP command-line interpreter: php app.phar. Well-known examples include composer.phar and phpunit.phar. Creating or modifying a Phar programmatically requires phar.readonly=0 in php.ini, which is set to 1 (read-only) by default.

Security concerns regarding PHAR files

Since PHP 5.3.0, Phar support is enabled by default. Automatic PHAR code execution in a PHP environment poses serious system security risks. There are known cases where malicious PHP code was distributed in PHAR files masked as JPEG or .txt files using simple extension replacement. Opening such a file may cause the system to become infected with malicious software. Additionally, triggering Phar stream wrappers (phar://) on attacker-controlled file paths can unserialize embedded metadata and lead to object-injection remote code execution.

Security & safety

RISK: HIGH

A PHAR is executable PHP code, so treat it like any program: run only Phars from trusted, official sources (composer.phar from getcomposer.org, phpunit.phar from phpunit.de), and verify the published checksum/signature when provided. Beyond running them, Phars are a notorious server-side attack vector: the phar:// stream wrapper can unserialize embedded metadata, enabling PHP object-injection / remote code execution if an application passes attacker-controlled paths to file functions. Never run an unsolicited .phar, and on servers avoid feeding user input into functions that can resolve phar:// paths.

Format details

in a nutshell
FULL NAMEPHP Archiveaka PHAR archive, PHP Archive package
DEVELOPERGreg Beaver / PHP project (PEAR)since 2008 (Phar extension bundled in PHP 5.3)
MIME TYPEapplication/x-php-archive
TYPESelf-contained PHP application/library archive (executable bundle)
STANDARDOpen · royalty-free

Programs that open PHAR files

Windows2 apps
7-Zip Open-source If the Phar uses tar/zip layout, copy it to tool.tar/tool.zip and open with 7-Zip to inspect files without running code.
PHP (CLI) Open-source Open a terminal and run php tool.phar (or php tool.phar --help) to execute it.
macOS1 app
PHP (CLI) Open-source Run php tool.phar in Terminal (PHP is available via Homebrew/macOS).
Linux1 app
PHP (CLI) Open-source Run php tool.phar, or chmod +x tool.phar && ./tool.phar if it has a shebang stub.

Technical details

deep spec
Entry point (stub)Executable PHP stub ending with `__HALT_COMPILER();` token, which marks the start of the binary manifest
Trailing signature magicGBMB 4-byte magic in the trailing signature block (present only in signed Phars)
CompressionNone, Zlib (gzip), or Bzip2 - configurable per-file or for the whole archive
Signature algorithmsMD5, SHA-1, SHA-256, SHA-512, or OpenSSL X.509 (controlled by phar.require_hash in php.ini)
Execution methodRun directly with `php app.phar`; no extraction required
Creation requirement`phar.readonly=0` must be set in php.ini to create or modify Phar files at runtime
Internal layoutPHP stub + binary manifest (file list, API version, flags) + file data + optional signature block
Byte orderLittle-endian
Typical sizeTens of KB to tens of MB (e.g., composer.phar ~2 MB, phpunit.phar ~3 MB)
PHP version supportBundled by default since PHP 5.3 (2009); maintained through PHP 8.x
Security riskPhar deserialization via `phar://` stream wrapper on attacker-controlled paths can trigger object-injection RCE
Supported payload layoutsFlat Phar, tar-based Phar, or zip-based Phar (PHP selects the format from the manifest)
Released2008 (Phar extension bundled in PHP 5.3)
Latest versionMaintained as a core PHP extension (current through PHP 8.x)
Open standardYes · royalty-free
Specificationwww.php.net

PHAR conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with PHAR files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about PHAR files.

Frequently asked questions

How do I run a PHAR file?
From a terminal with PHP installed: php tool.phar. On Linux/macOS you can also chmod +x tool.phar && ./tool.phar if it has a shebang. Double-clicking usually won't work.
What is a PHAR file?
A PHP Archive - an entire PHP application or library packaged into one executable file, like a Java JAR. Composer and PHPUnit are distributed this way.
How do I open a PHAR to see what's inside?
Without running it: copy it to .tar or .zip (many Phars use those layouts) and open with 7-Zip, or use PHP's Phar API to extract the files.
Is it safe to run a PHAR file?
Only from trusted sources. A Phar contains runnable code, and the Phar stream wrapper has a known object-injection/RCE attack class, so never execute an unknown .phar.
Why won't my PHAR run - 'phar.readonly' error?
Running a Phar is fine, but creating/modifying one requires phar.readonly=0 in php.ini. If you only want to run it, that setting isn't needed.
Can I turn a PHAR into an EXE?
Not by conversion - a Phar needs PHP to run. Install PHP and run php tool.phar, or bundle PHP with the Phar using a dedicated packager if you truly need a standalone .exe.

References

1PHP Manual - Phar file formatwww.php.net
2PHP Manual - Introduction to Pharwww.php.net

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.BINCD/DVD Disc Image (BIN/CUE)
7.NOMEDIAAndroid No-Media Marker File
8.RPMSGRestricted Permission Message
9.MDMarkdown Document
10.TMPTemporary File

Related extensions

.APKAndroid Package
.EXEWindows Executable (Portable Executable)
.VBSVBScript file (Visual Basic Script)
.JARJava Archive
.EX4MetaTrader 4 Compiled Program (Expert Advisor / Indicator / Script)
.APPXMicrosoft Windows App Package (AppX)

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z