Download the PHP package andersonsalas/expressionlab without Composer
On this page you can find all versions of the php package andersonsalas/expressionlab. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download andersonsalas/expressionlab
More information about andersonsalas/expressionlab
Files in andersonsalas/expressionlab
Package expressionlab
Short Description Expression Lab is a sandboxed diagnostics and data inspection environment for WordPress.
License GPL-2.0-or-later
Informations about the package expressionlab
Expression Lab
An interactive diagnostics console and declarative DSL for WordPress.
Expression Lab is an experimental in-browser console for exploring WordPress data. Powered by a declarative Domain-Specific Language (DSL), it enables inspecting posts, options, database tables, and files without writing raw PHP snippets.
In WordPress development, troubleshooting often relies on ad-hoc PHP code execution, temporary var_dump() calls, or console plugins based on eval(). In production sites, unconstrained execution carries inherent risks: accidental database writes, memory exhaustion, or security exposure.
Expression Lab explores an alternative approach:
- Evaluating DSL expressions via an Abstract Syntax Tree (AST) powered by an extended Symfony Expression Language engine, rather than executing arbitrary PHP.
- Employing client-side cryptographic key derivation and server-side signature verification so credentials and private keys are never stored in the database.
- Providing operational boundaries, including in-memory SQLite mirroring (
Database.mirror()), read-only database defaults, filesystem path canonicalization, and CPU execution time limits.
Architecture & Execution Model
The diagram below illustrates the authentication and execution lifecycle:
Authentication operates through client-side key derivation and cryptographic request signing. The browser generates ephemeral keys in memory to sign each request, and the backend verifies the signature without storing master passphrases, private keys, or credentials in the WordPress database.
The runtime enforces strict operational boundaries. Expressions evaluate declaratively inside an isolated AST engine rather than arbitrary PHP execution, database operations default to read-only access, the console UI runs in a sandboxed iframe, and an execution timer acts as a CPU watchdog to terminate runaway requests.
For an in-depth breakdown of the cryptographic model, boundary limits, and threat assumptions, see the Security Model documentation.
The DSL at a Glance
Expression Lab provides fluent query interfaces for core WordPress entities and functional pipeline helpers:
Fluent Entity Queries
In-Memory SQLite Analytics
Mirroring tables allows running SQL queries:
Functional Pipeline Operations
Data transformations are composed using declarative special forms (prog, set, map, filter, var):
System Requirements
| Component | Requirement | Note |
|---|---|---|
| PHP | 8.2 – 8.5 |
Tested against PHP 8.2, 8.3, 8.4, and 8.5 |
| WordPress | 6.4+ |
Tested on modern WordPress releases and Core trunk |
| PHP Extensions | sodium, sqlite3 |
sodium for Ed25519 signature verification; sqlite3 for in-memory database mirroring |
| Environment | Single-site & Multisite | Automated tests run against both configurations |
| Browser | Modern Chromium, Firefox, or Safari | Requires native Web Crypto API support |
Installation & Setup
[!WARNING] Expression Lab is currently experimental alpha software intended for staging, local development, and sandboxed diagnostic environments. It has not undergone third-party security audits. Do not use in production or business-critical environments. Provided under the GPL-2.0 license without warranty.
1. Installation
Pre-built ZIP Archive (Recommended)
Pre-built release packages are distributed as .zip archives via GitHub Releases. These include bundled frontend assets and scoped dependencies, installable through Plugins → Add New Plugin → Upload Plugin in the WordPress administration dashboard.
From Source (Development)
For local development, source builds, or code contributions:
-
Clone the repository into the WordPress plugins directory:
-
Install PHP dependencies:
(For a lightweight test build without development tooling, use
composer install --no-dev --optimize-autoloader). - Install JavaScript dependencies and compile frontend assets:
2. Configuration
- Navigate to Tools → Expression Lab in the WordPress administration dashboard as an administrator.
- Complete the initial security onboarding wizard by defining a master passphrase.
-
The wizard outputs the required configuration constants. Append them to
wp-config.php: - Once defined in
wp-config.php, reload the administration interface.
Development & Tooling
The repository provides automated validation, asset compilation, and a local documentation environment:
Code Quality & Automated Tests
Frontend Assets & Live Reload
[!TIP] Frontend Development with Hot Reload: In production, the console UI executes inside an isolated
iframewith a unique origin (null). Because modern browsers blocklocalStorageaccess in sandboxed iframes withoutallow-same-origin, tools like Vue and Pinia hot reload require disabling the iframe sandbox during local UI development:Ensure this remains enabled outside of UI development sessions.
Documentation (Docusaurus)
The documentation site is located in the docs/ workspace:
Documentation
Full syntax guides and API references are available on the project's official website:
- Getting Started: Installation & Configuration
- Language Reference: Basic Syntax · Scripting
-
API Reference: Database · Options · Network Sites · Users · Posts · Media · Files · HTTP · Console · IP Lookup · Graph
- Security & Environment: Security Model
Documentation is available in Spanish.
Contributing
Contributions, feedback, and technical proposals are managed according to the guidelines in CODE_OF_CONDUCT.md.
- Branching Strategy:
- The
masterbranch is the central integration branch and always reflects the latest tested code. - Working branches should originate from and target
mastervia Pull Requests using standard prefixes: fix/<description>for bug fixes.improve/<description>for performance, documentation, or tooling improvements.feature/<description>for new capabilities.- Releases are cut from
masterusing semantic version tags (v*).
- The
- Pull Requests: Pull requests should provide a clear rationale for the change. Rigid commit formats are not required; descriptive clarity is sufficient.
- Validation: All pull requests must pass the automated GitHub Actions checks (linting and test suites). Running
pnpm run lintandpnpm run testlocally prior to submission is recommended to catch issues early.
Security Inquiries
Potential security vulnerabilities should not be reported through public issue trackers. Consult SECURITY.md for supported versions and coordinated disclosure procedures.
Reports may be submitted via the GitHub Security Advisories interface or by emailing [email protected].
License
Expression Lab is open-source software distributed under the terms of the GNU General Public License v2.0 or later (GPL-2.0-or-later).
All versions of expressionlab with dependencies
phpdocumentor/reflection-docblock Version ^6.0
maxmind-db/reader Version ^1.14
splitbrain/php-archive Version ^1.5