What is the PHAR file format?
.phar files are associated with the PHP development environment. A .phar archive is the PHP equivalent of a JAR file - it packages an entire PHP application or library into a single self-contained, executable bundle that can be distributed as one file.
What kind of data can PHAR files contain?
.phar archives store PHP scripts and any supporting assets (templates, configs, resources), optionally compressed with gzip or bzip2 on a per-file or whole-archive basis. Every .phar file contains an executable PHP stub, a binary manifest listing the bundled files with metadata, and an optional cryptographic signature (MD5, SHA-1, SHA-256, SHA-512, or OpenSSL) verified via phar.require_hash.
How can I run PHAR files?
.phar files can be run directly with the PHP command-line interpreter: php app.phar. Well-known examples include composer.phar and phpunit.phar. Creating or modifying a Phar programmatically requires phar.readonly=0 in php.ini, which is set to 1 (read-only) by default.
Security concerns regarding PHAR files
Since PHP 5.3.0, Phar support is enabled by default. Automatic PHAR code execution in a PHP environment poses serious system security risks. There are known cases where malicious PHP code was distributed in PHAR files masked as JPEG or .txt files using simple extension replacement. Opening such a file may cause the system to become infected with malicious software. Additionally, triggering Phar stream wrappers (phar://) on attacker-controlled file paths can unserialize embedded metadata and lead to object-injection remote code execution.
Security & safety
RISK: HIGHA PHAR is executable PHP code, so treat it like any program: run only Phars from trusted, official sources (composer.phar from getcomposer.org, phpunit.phar from phpunit.de), and verify the published checksum/signature when provided. Beyond running them, Phars are a notorious server-side attack vector: the phar:// stream wrapper can unserialize embedded metadata, enabling PHP object-injection / remote code execution if an application passes attacker-controlled paths to file functions. Never run an unsolicited .phar, and on servers avoid feeding user input into functions that can resolve phar:// paths.
Format details
in a nutshellPrograms that open PHAR files
php tool.phar (or php tool.phar --help) to execute it. php tool.phar, or chmod +x tool.phar && ./tool.phar if it has a shebang stub. Technical details
deep spec| Entry point (stub) | Executable PHP stub ending with `__HALT_COMPILER();` token, which marks the start of the binary manifest |
| Trailing signature magic | GBMB 4-byte magic in the trailing signature block (present only in signed Phars) |
| Compression | None, Zlib (gzip), or Bzip2 - configurable per-file or for the whole archive |
| Signature algorithms | MD5, SHA-1, SHA-256, SHA-512, or OpenSSL X.509 (controlled by phar.require_hash in php.ini) |
| Execution method | Run directly with `php app.phar`; no extraction required |
| Creation requirement | `phar.readonly=0` must be set in php.ini to create or modify Phar files at runtime |
| Internal layout | PHP stub + binary manifest (file list, API version, flags) + file data + optional signature block |
| Byte order | Little-endian |
| Typical size | Tens of KB to tens of MB (e.g., composer.phar ~2 MB, phpunit.phar ~3 MB) |
| PHP version support | Bundled by default since PHP 5.3 (2009); maintained through PHP 8.x |
| Security risk | Phar deserialization via `phar://` stream wrapper on attacker-controlled paths can trigger object-injection RCE |
| Supported payload layouts | Flat Phar, tar-based Phar, or zip-based Phar (PHP selects the format from the manifest) |
| Released | 2008 (Phar extension bundled in PHP 5.3) |
| Latest version | Maintained as a core PHP extension (current through PHP 8.x) |
| Open standard | Yes · royalty-free |
| Specification | www.php.net |
PHAR conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about PHAR files.
Frequently asked questions
How do I run a PHAR file?
php tool.phar. On Linux/macOS you can also chmod +x tool.phar && ./tool.phar if it has a shebang. Double-clicking usually won't work.What is a PHAR file?
How do I open a PHAR to see what's inside?
Is it safe to run a PHAR file?
Why won't my PHAR run - 'phar.readonly' error?
Can I turn a PHAR into an EXE?
php tool.phar, or bundle PHP with the Phar using a dedicated packager if you truly need a standalone .exe.