Database Search and Replace Script in PHP

Search Replace DB version 3.1.0 is a user-friendly, front-end tool for developers, that allows you to carry out database wide search/replace actions, that don't damage PHP serialized strings or objects.


It has come to our attention that some users have been leaving this script on their servers despite advice to the contrary. Due to the very real dangers, it can present when used that way, we now ask that you complete a form where we make sure you’re aware of these risks in order to receive the download link. Do also carefully read the installation instructions below.

Please check your spam folder for the download link before you email us for support. If you are still experiencing problems, email us politely with your query.


Download the script from the link you received by email, and install it to a secret folder with an obfuscated name. Your server should also not be set to provide directory lists.

A typical WP install with this script would have the folders as follows:


Do not install Search Replace DB to the root folder or in WP’s own folder hierarchy or you risk all sorts of potential problems. Just don’t. It must run in its own folder.

To see how you can use this tool to aid migrations, check out our article on WordPress migrations or visit the WP Tuts+ article that mentions this script.

If you are in any doubt whatsoever about how to use this standalone script, then please consider getting an expert in. It’s a really powerful bit of code that if used badly can damage a WP install beyond repair. If you want help, get in somebody like us, for example, or any of the other great guys listed over at CodePoet.


The code is supplied under the GPL V3 and is fully open source. Do be aware that this means people can change this code and offer it up, and that other versions may be worse… or better. It is code for developers, by developers, and you should only use code from sources you trust.


Please beware of adverts below that offer a download button, but adverts do allow us to partly cover the cost of running this project.


Where do I install the unzipped files?

In a directory on your webserver. It can be an httpauth protected folder if it’s a public facing webserver.

I heard this script is insecure. Is it really?

Yes – it’s a development tool, not something you should be putting on production servers. If you do put it on a production server be really careful. We’re trying to work out ways of protecting users further, because it turns out that this tool is being recommended by webhosts around the world, but too often to quite naive users who don’t really understand the risks.

I get an error 2: Class __PHP_Incomplete_Class has no unserializer

This is a common error and generally comes up with users of Yoast plugins, but also some others. It’s something we’re aware of. In the vast majority of cases everything is fine. You could try running the script from a different PHP install – there is no reason why you can’t have a pipe to a production database and connect to it from your workstation, for example. A little more detail is on our github repository.


Test 20160504

  • Version 3.1.0 (Web UI and CLI versions) tested against PHP 7.0.6 and functioned correctly.
  • Version 2.1.0 confirmed to not work with PHP 7.0.6 but is kept for use on older servers.

Version 3.1.0:

  • Safety checks to prevent deletion when installed incorrectly. However, you should still take care when dealing with files on your server.
  • JavaScript popup confirmation on ‘Delete Me’.
  • Port number option in both the GUI and CLI. Use –port nnn to set a non-default MySQL port.
  • Fixed Drupal bootstrap behaviour. Start up of script uses Drupal data as guide, no longer relies on a full successful Drupal initialisation before script will allow you to proceed.
  • Driver selection improved so that PDO will be attempted first if PDO+mysql is available, with mysqli being used as a fallback. This fixes ‘driver not found’ errors
  • Removed mysql_ functions and replaced with mysqli_.
  • Improved JS preview overlay for dry runs. This means that the right pane will always show the most accurate data possible. If serialised strings are present, highlights are not displayed.

Version 3.0.0:

  • Major overhaul
  • Multibyte string replacements
  • UI completely redesigned
  • Removed all links from script until ‘delete’ has been clicked to avoid security risk from our access logs
  • Search replace functionality moved to it’s own separate class
  • Replacements done table by table to avoid timeouts
  • Convert tables to InnoDB
  • Convert tables to utf8_unicode_ci
  • Use PDO if available
  • Preview/view changes
  • Optionally use preg_replace()
  • Scripts bootstraps WordPress/Drupal to avoid issues with unknown serialised objects/classes
  • Added marketing stuff to deleted screen (sorry but we’re running a business!)

Version 2.2.0 (never formally released but patched into v3.0.0):

For changes prior to v2.2.0 please refer to index.php where you will find a complete changelog. You can also browse the project on github.

To Be Done

  • Ensure UTF8 encoding is enforced (see comments). Added in v2.1.0
  • Self deletion or security system to prevent accidental security risks. Added in v3.0.0
  • Release CLI version for use on non-WP sites, or for other purposes (already supports use on any MySQL DB.) Added in v3.0.0
  • Change to GPL V3. Added in v3.0.0
  • Eliminate warnings and remove deprecated function calls. Added in v2.1.0
  • Add facility to subscribe to interconnect/it Newsletter. Added in v3.0.0
  • Confirm deletion has actually happened.
  • Add old versions for download to this page.


We’d love to get contributions, bug reports and more on the Search Replace DB github repository. Please come on over – you’ll be more than welcome but you will need to request access by emailing [email protected]


We’ve been asked a lot in the comments box below about accepting donations. But you can’t believe what a headache that is from an accounting and tax perspective.

Consequently all we can say is that if you wish to you can buy a personal gift for the key developers from one of the wishlists below – especially given that it’s a spare time project. If others who have contributed wish to provide us their wishlist links then we’d be more than happy to add them.

1,562 responses to “Database Search and Replace Script in PHP

  1. Been using the tool for years. For the most part it has been bulletproof, Thanks for that! However just came across a situation where it is failing. Working on a Drupal DB. Need to update a single table/field ‘field_data_body’ / ‘body_value’ . Search/Replace strings ‘src=”/sites/default/files’ | ‘src=”/subfolder/sites/default/files’. The result states that 377of533 rows have been updated, however the reality is ALL 533 ‘body_value’ fields (the entire table) have been replaced with identical data that appears to be from one of the other rows. Thanks for any assistance.

    1. That’s strange. I mean, searching for things with a slash in is common and normal.

      Is there anything particularly strange about the data or table format? We get a lot of queries, but rarely a database dump to work with.

  2. Hi is this possible to replace links with multiple database?

  3. Fantastic tool! Works like a dream… saved me hours.

  4. escape characters? I’m trying to replace (really just get rid of) a string that includes a call to a script that’s all over my wordpress pages/posts … there’s single quotes, slashes, etc. Do I have to escape characters to get it to work? It seems to do a good dry run if I search for just part of the url.

    1. The search is rather absolute in how it works. If you search for & it won’t find the HTML & – it’ll just find the first character.

  5. I’m getting 6 false positives on wp_options and 41 on wp_postmeta whenever i search for a string that doesn’t exist. viewing the details shows the same before and after with no instance of the string. any ideas?

    1. Sounds peculiar – what sort of string are you searching for?

  6. Great tool!

    Just a heads up on some records it seems not to be able do to the replaces:

    – table wp_options, _wc_session_* records:

    – table wp_followup_customer_carts:

    1. There’s no particular reason why it wouldn’t work for this other than, perhaps, the row being locked when you tried to update. Is this on a live website? You may have to close it for maintenance first.

  7. I read about this script from our host provider and just did our 1st run after a site migration. Pretty awesome! And the dry run feature is very cool. Nice job!

  8. This is such a great tool, thanks a lot !!! It saved me a lot of time and headaches…

  9. Hi there, thanks so much for this tool, it’s really a great help.

    One thing – does it work if the database’s table names have been changed from the default wp_ ?


    1. Yes. It works on any table, including non-WP ones.

    2. I had the same. I think the problem was that I had capital letter in my prefix. Just changed it to small one in wp-config 🙂

  10. Great tool, especially the ‘dry run’, to test before you do.

Comments are closed.