symfony/var-dumper
55.9
Adequate · 26 September 2026
7.9k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a PHP debugging component that provides a \dump()\ function as a modern replacement for \var\_dump()\, capable of inspecting variables across CLI, HTML, and server-based contexts. It features a robust cloning engine that handles complex PHP types and objects with semantic clarity, alongside a centralized server architecture for aggregating and displaying dump data. The component supports rich contextual metadata, customizable output formatting, and secure handling of sensitive data through CSP and input escaping.
How it got here
2014 — VarDumper component creation and modernization
9 changes.
This period marks the initial release and subsequent modernization of the VarDumper component, introducing a superior debugging alternative to var\_dump with support for modern PHP features and complex object inspection. The work involved a significant architectural refactor of the Cloner and Dumper components to leverage PHP 8+ capabilities, alongside the addition of comprehensive casters for various extensions and robust test coverage.
2015–2023 — VarDumper server and context features
15 changes.
This period focused on expanding the VarDumper component with a centralized server for collecting and displaying dump data across CLI and web contexts. It introduced new command-line and HTML descriptors, context providers for richer metadata, and the necessary client-server communication infrastructure. Comprehensive test coverage was added to validate the new features, including security measures against injection and robust handling of various data types.
Features
Add dump() and dd() debugging helper functions
The application now includes global \dump()\ and \dd()\ helper functions in \Resources/functions/dump.php\ to simplify variable inspection during development. The \dump()\ function accepts variadic arguments, supports named arguments for clearer output labels, and returns the inspected values to allow chaining. The \dd()\ function (dump and die) behaves similarly but terminates script execution after dumping; in web contexts, it also sends a 500 Internal Server Error header to indicate an abnormal termination, while in CLI environments it exits with code 1.
Resources/functions · high confidence
Initial release of the VarDumper component
This change introduces the VarDumper component, providing a \dump()\ function as a superior alternative to \var\_dump()\ for inspecting PHP variables. The component includes a \VarDumper\ class that manages cloners and dumpers, supporting output formats via the \VAR\_DUMPER\_FORMAT\ environment variable (html, cli, or server). It features context-aware dumping (source location, request context), keyboard-accessible HTML toggles, and support for various PHP extensions and types (FFI, Fiber, WeakMap, UUIDs, etc.). The release also includes test infrastructure via \phpunit.xml.dist\ and distribution packaging via \.gitattributes\.
(repo-wide) · high confidence
New CLI and HTML descriptors for VarDumper command output
The VarDumper command now uses dedicated descriptor classes to format dump output. The new CliDescriptor renders dumps in the terminal using Symfony Console's table and section helpers, escaping context strings to prevent terminal injection. The new HtmlDescriptor generates styled HTML output, including hyperlinks for source files, tags for controller and project directory context, and unique deduplication identifiers. A common DumpDescriptorInterface defines the contract for these formatters.
Command/Descriptor · high confidence
New CSS and JS assets for the HTML VarDumper descriptor
Added \Resources/css/htmlDescriptor.css\ and \Resources/js/htmlDescriptor.js\ to style and enhance the HTML output of the VarDumper component. The CSS provides a modern layout with specific syntax highlighting for dumped variables and prevents selection of control characters, while the JavaScript automatically hides duplicate headers in the dump list to reduce visual clutter.
Resources/css · high confidence
New context providers for CLI, HTTP requests, and source code
The VarDumper component now includes a new ContextProviderInterface and three implementations: CliContextProvider (provides command-line arguments and a unique identifier for CLI dumps), RequestContextProvider (provides URI, HTTP method, and controller information for web requests), and SourceContextProvider (provides file, line, code excerpt, and project directory details for source-based dumps). These providers enable richer contextual metadata to be attached to dump data, particularly when sending dumps to a server dumper.
Dumper/ContextProvider · high confidence
New server:dump command for centralized dump collection
A new \server:dump\ command has been added to the VarDumper component, allowing users to start a dedicated server that collects and displays \var\_dump\ output in a single place. This command supports multiple output formats, including CLI and HTML, and integrates with shell completion for easier usage. It provides a centralized way to debug applications by aggregating dump data from various sources.
Command · high confidence
Standalone VarDumper server script added
A new executable script, Resources/bin/var-dump-server, has been added to allow starting the VarDumper server independently. This script bootstraps the Symfony Console application and the DumpServer, enabling users to collect and output dumps in multiple formats from a single place. It includes a guard to ensure it is only run in CLI contexts and handles autoloading from various Composer directory structures.
Resources/bin · high confidence
VarDumper casters for AddressInfo, AMQP, and FFI types
The VarDumper component now includes dedicated casters for AddressInfo, AMQP, and FFI objects. AddressInfo dumps are enhanced with human-readable flag and protocol names. AMQP connections, channels, queues, exchanges, and envelopes are now displayed with their internal properties (such as login, host, and message headers) and exchange types. FFI CData and CType instances are cast to show their type details, size, alignment, and string contents, with memory access restricted to the current page to prevent crashes.
Caster · high confidence
VarDumper component restructured with new dumper architecture and CSP support
The VarDumper component has been refactored to introduce a new \AbstractDumper\ base class and a \DataDumperInterface\, establishing a cleaner separation between dumping logic and data cloning. This change adds a \ContextualizedDumper\ to attach metadata to dumps via context providers and a \ServerDumper\ to forward serialized data to an external server. For users, the \HtmlDumper\ now supports configurable themes (light and dark) and includes Content Security Policy (CSP) nonce injection for both scripts and styles, while the \CliDumper\ offers improved color handling and display options.
Dumper · high confidence
VarDumper: New server-side dump collection and client connection components
The VarDumper component now includes dedicated classes for server-based dump collection. The new \Server\\Connection\ class handles the client side, establishing a TCP connection to a specified host and sending serialized \Data\ objects along with context information. The new \Server\\DumpServer\ class implements the server side, listening for incoming connections, receiving payloads, and deserializing them using a restricted set of allowed classes (\Data\, \Stub\, \ClassDumpStub\) for security. It logs received payloads and passes the deserialized data and context to a provided callback for processing.
Server · high confidence
Behavioural changes
Simplified ThrowingCasterException constructor and error message
The ThrowingCasterException class no longer accepts a caster argument in its constructor; it now only takes the previous throwable. The exception message has been updated to explicitly state that an unexpected exception was thrown from a caster, using the previous exception's class name and message for context.
Exception · high confidence
VarDumper Cloner rewritten for modern PHP and expanded type support
The VarDumper Cloner component has been significantly refactored to support PHP 8+ features and modernize its internal architecture. The legacy PhpCloner has been removed and replaced by a new VarCloner that uses a breadth-first queue algorithm and native PHP 7.4+ features like ReflectionReference for accurate hard-reference detection. The core data structures have been updated: the Stub class now uses typed properties and optimized serialization, the Cursor class provides detailed dumping state, and the Data class now implements ArrayAccess, Countable, IteratorAggregate, and Stringable for better usability. Additionally, the AbstractCloner now includes a comprehensive set of default casters for a wide range of PHP extensions (DOM, PDO, Reflection, Spl, Intl, Redis, Memcached, etc.) and Symfony components, ensuring that complex objects are dumped with semantic clarity rather than raw internal state.
Cloner · high confidence
Test coverage
Added VarDumperTestTrait for standardized dump assertions; Added test coverage for VarDumper casters; Added test coverage for VarDumper dumpers and functions; Added test fixtures for VarDumper coverage; Added tests for RequestContextProvider; Added tests for VarDumper CLI and HTML descriptors; Added tests for VarDumper Server Connection; Added tests for VarDumperTestTrait configuration and non-scalar expectations; Added tests for dump() and dd() function behaviors; Added tests for server:dump command completion; Added unit tests for VarDumper Cloner components.
Dependencies
Symfony VarDumper requires PHP 8.4.1 and updates Symfony dependencies
The VarDumper component now requires PHP 8.4.1 or higher, reflecting a significant shift in minimum runtime requirements. Additionally, development dependencies for Symfony Console, HttpKernel, Process, and Uid have been updated to support versions 7.4 and 8.0, while the Twig dependency now allows versions 3.12 and 4.0. These changes ensure compatibility with the latest Symfony ecosystem versions and modern PHP features.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 45 → 56 (+10.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 91 → 80 (-10.7)
- Architecture 96 → 97 (+1.7)
- Maturity 49 → 48 (-1.1)
- Readiness 17 → 43 (+26.0)
- Security 97 → 97 (-0.8)
Resolved (10)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (6 lines × 2) (Tests/Caster/DateCasterTest.php)
- Duplicated block (6 lines × 2) (Tests/Caster/FFICasterTest.php)
- Duplicated block (7 lines × 2) (Cloner/Stub.php)
- Duplicated block (8 lines × 2) (Tests/Caster/IntlCasterTest.php)
- No exposed public API
- No tests found
- Test reliability not included
- The README describes VarDumper as a 'better dump()' function instead of var_dump(), but no code example shows how to call dump() or walk through a variable. (README.md)
New (77)
- AbstractCloner.castObject (cognitive 19) (Cloner/AbstractCloner.php)
- AbstractDumper.utf8Encode (cognitive 16) (Dumper/AbstractDumper.php)
- Caster.castObject (cognitive 33) (Caster/Caster.php)
- Caster.castObject (cyclomatic 19) (Caster/Caster.php)
- Caster.filter (cognitive 22) (Caster/Caster.php)
- Caster.filter (cyclomatic 21) (Caster/Caster.php)
- ClassStub.__construct (cognitive 24) (Caster/ClassStub.php)
- ClassStub.__construct (cyclomatic 20) (Caster/ClassStub.php)
- CliDumper.dumpKey (cognitive 43) (Dumper/CliDumper.php)
- CliDumper.dumpKey (cyclomatic 21) (Dumper/CliDumper.php)
- CliDumper.dumpString (cognitive 67) (Dumper/CliDumper.php)
- CliDumper.dumpString (cyclomatic 28) (Dumper/CliDumper.php)
- CliDumper.enterHash (cognitive 24) (Dumper/CliDumper.php)
- CliDumper.enterHash (cyclomatic 21) (Dumper/CliDumper.php)
- CliDumper.style (cognitive 46) (Dumper/CliDumper.php)
- CliDumper.style (cyclomatic 32) (Dumper/CliDumper.php)
- CliDumper.supportsColors (cyclomatic 17) (Dumper/CliDumper.php)
- Data.dumpItem (cognitive 55) (Cloner/Data.php)
- Data.dumpItem (cyclomatic 31) (Cloner/Data.php)
- Data.getValue (cognitive 20) (Cloner/Data.php)
- …and 57 more
Changes since last survey
- 32 commits — 26 feature/other, 6 fixes
By area
- (repo) — 19 commits
- Tests/Caster — 3 commits
- Caster/SplCaster.php — 2 commits
- Command/Descriptor — 2 commits
- (root) — 1 commit
- Caster/DateCaster.php — 1 commit
- Dumper/CliDumper.php — 1 commit
- Server/DumpServer.php — 1 commit
- Tests/Command — 1 commit
- Tests/Dumper — 1 commit
Notable commits
- fix: Revert "Give the Redis test probes an explicit connect timeout"
- fix: [VarDumper] Fix division by zero when dumping a DatePeriod whose interval does not move forward
- fix: [VarDumper] Fix dumping class names to the dump server
- fix: [VarDumper] Fix losing colors when dumping to php://output on the CLI
- fix: [VarDumper] Fix the RdKafka caster tests with librdkafka 2
- fix: bug #65691 [VarDumper] Escape context strings in HtmlDescriptor (nicolas-grekas)
- change: Give the Redis test probes an explicit connect timeout
- change: Merge branch '5.4' into 6.4
- change: Merge branch '5.4' into 6.4
- change: Merge branch '5.4' into 6.4
- change: Merge branch '5.4' into 6.4
- change: Merge branch '6.4' into 7.4
- change: Merge branch '6.4' into 7.4
- change: Merge branch '6.4' into 7.4
- change: Merge branch '6.4' into 7.4
- change: Merge branch '6.4' into 7.4
- change: Merge branch '7.4' into 8.1
- change: Merge branch '7.4' into 8.1
- change: Merge branch '7.4' into 8.1
- change: Merge branch '7.4' into 8.1
- …and 12 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
symfony/var-dumper was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2822eb9093ca83d9526dc784b43fd5d91e46cea3 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.