=== Fruti Serialized Data Audit ===
Contributors: frutilabs
Tags: serialized data, unserialize, database, migration, debug
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Audit SQL dumps for broken PHP serialized values before import. Reports findings only, never changes data.

== Description ==

A plain find-and-replace on a WordPress database, or a hand-edited export, changes the text inside
serialized values but not the byte-length prefix PHP stored with every string. The import then
reports success, and widgets, theme settings, page-builder layouts or plugin options quietly
disappear. This plugin reads a `.sql` dump, parses every serialized payload it finds, and lists the
ones that are structurally broken, with the line number, the table it belongs to, the reason and a
short snippet.

Detected structural problems:

* `string_length_mismatch` - a string's declared byte length no longer matches its content, the
  classic result of a naive search-and-replace or of a UTF-8/latin1 conversion.
* `count_mismatch` - an array or object declares more items than it contains.
* `truncated` - the payload ends in the middle of a structure.
* `invalid_type` - a payload starts but the expected next token is not a valid serialized value.

Supported serialization tokens: `N`, `b`, `i`, `d`, `s`, `a`, `O`, `r`, `R`, `E` and `C`, in both
plain and `mysqldump`-escaped form. `C:` payloads are treated as opaque bytes and are never parsed
recursively.

The plugin never modifies your data. It does not import the dump, does not connect to the database,
does not execute SQL and does not write a repaired file. It only reports.

= How to use it =

1. Export the database you are about to import: `mysqldump -u user -p dbname > dump.sql`.
2. Open Tools -> Fruti Serialized Data Audit, choose that `.sql` file and press Run Audit.
3. Read the summary and the list of broken payloads: status, table, line, reason and snippet.
4. Fix the cause with `wp search-replace` or a serialization-aware replacement, export a fresh dump
   and audit it again.

= Privacy =

The uploaded SQL file is processed locally on your own WordPress server. It is analysed in PHP's
upload temporary file: it is not copied into the media library, not placed in `wp-content/uploads`,
not saved in the plugin directory, not stored in the database and not written to logs or cache. The
plugin makes no network requests, sends no telemetry and does not transmit the dump anywhere.

= Support =

Questions, bug reports and support: hello@fruti.lt

== Installation ==

1. Upload the plugin folder to `/wp-content/plugins/`, or install the ZIP through
   Plugins -> Add New -> Upload Plugin.
2. Activate the plugin through the Plugins screen.
3. Go to Tools -> Fruti Serialized Data Audit.

== Frequently Asked Questions ==

= Does the plugin change or repair my dump? =

No. It is strictly read-only and reports findings only. Fix the underlying cause (use
`wp search-replace` or a serialization-aware replacement), then export a new dump and audit it again.

= Which file types are accepted? =

Only `.sql`. Archives such as `.zip` or `.gz` are not unpacked: extract the dump first.

= What happens with very large dumps? =

The dump is read into memory for analysis, so extremely large files may exceed the memory limit of
your server. The plugin refuses files above 256 MB and shows a message; split larger dumps and audit
the parts separately.

= Does the plugin send my dump anywhere? =

No. Everything happens inside your own admin request on your own server. There is no external
service, no account, no API call and no telemetry, and the uploaded file is discarded when the
request ends.

== Screenshots ==

1. The audit result after a run: how many structurally broken payloads were found in the uploaded dump.
2. The findings table: line, table, reason and snippet for every broken payload, read-only and nothing changed.

== Changelog ==

= 1.0.0 =
* First release. Bundles parser core 1.0.4, which supports `N`, `b`, `i`, `d`, `s`, `a`, `O`, `r`,
  `R`, `E` and `C` tokens in plain and `mysqldump`-escaped form.
