Download the PHP package jonpurvis/fuzz without Composer

On this page you can find all versions of the php package jonpurvis/fuzz. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package fuzz

Fuzz - Coverage-guided fuzzing for Pest

A PestPHP plugin that wraps nikic/php-fuzzer so you can write coverage-guided fuzz tests in the Pest style you already know and love: drop a fuzz(...)->run() call inside a normal test(), and it sits alongside the rest of your suite. Under the hood, the fuzzer is steered by which lines of your code each input actually runs. Meaning: if a mutated input only revisits the same happy-path lines the seed already hit, it gets discarded; if it suddenly takes a different if / null / error path, that input is kept and mutated further. That is what “coverage-guided” is.

Tests GitHub last commit Packagist PHP Version GitHub issues GitHub Packagist Downloads

Introduction

Fuzz is a PestPHP plugin for coverage-guided fuzz testing. It searches for inputs that crash your code (or break invariants), using the familiar Pest syntax so fuzz cases read like any other test in your suite.

Pest datasets are great for confirming cases you already thought of. Fuzz mutates seeds, keeps the ones that run new lines of your code, and hunts for the cases you forgot — TypeErrors, non-finite math, leaky sanitizers, hostile JSON shapes, and more.

Requires PHP 8.4+ and Pest 5:

Examples

Let's say your app handles Stripe-style webhooks and trusts the decoded JSON a little too much:

That helper is open to hostile shapes you probably never typed by hand: null, [], {}, {"type":"ping"}, truncated JSON, nested junk, and whatever else arrives on the wire.

You could cover it with a Pest dataset — a predetermined list of values you already thought of:

Datasets are great for regressions and examples you care about by name. They only ever send what you listed.

Or you could use fuzz testing — because the input space is huge, and the fuzzer keeps mutating around your seeds (preferring inputs that hit new lines) until something crashes:

Prefer static callables (or Closure::fromCallable) so the isolated worker does not need Pest's generated test class.

Unlike a dataset, this does not check a fixed list of JSON strings. It searches:

  1. Starts from seed(...) — your known-good examples become the initial library.
  2. Mutates those bytes repeatedly (flip/delete/insert, splice in dictionary tokens).
  3. Watches which lines of your PHP ran for that input (coverage).
  4. If the input hit something new, keeps it and mutates it further. If it only revisited the same lines as before, throws it away.
  5. Fails the Pest test if the target throws an uncaught Error / TypeError / times out — and, with saveCrashes() (default), writes the payload to .pest/fuzz-crashes/{hash}/crash-*.txt.

That loop is what coverage-guided means. Imagine your seed only walks the happy path. A mutation that still only walks that path teaches the fuzzer nothing, so it moves on. A mutation that suddenly takes a different if / switch / error branch is interesting: the fuzzer keeps that input and breeds more variants from it. Over thousands of runs, that pushes the search toward the weird shapes that actually stress your code, instead of wasting the budget on noise that never leaves the happy path.

So a dataset answers “do these cases I thought of behave?” This fuzz test answers “can we find a case I did not list that still breaks eventName?”

Starting from a seed like {"event":"invoice.paid","id":"in_123"}, mutations might wander into inputs such as:

You would rarely hand-author all of those into a dataset. The fuzzer is there to stumble into them (and similar) within the runs budget.

What the chain is doing:

Use both: datasets lock in known good/bad cases; fuzz hunts for the ones you forgot. When fuzz finds a crash, paste that payload into a named dataset so it never slips back in.

Method Meaning
runs(int) Max target executions (default 1000)
maxLen(int) Max input byte length
timeout(int) Per-input seconds (pcntl)
withDictionary(array) .dict paths and/or keyword strings
seed(array) Starting example inputs (strings or files)
libraryDir(string) Where interesting inputs are kept (default .pest/fuzz-library/{hash})
crashDir(string) Where crashes are saved (default .pest/fuzz-crashes/{hash})
saveCrashes(bool) Persist crashing inputs to crashDir as crash-*.txt (default true; does not suppress the failure)
allow(array) Domain exception classes to ignore
run() Execute in an isolated worker

Contributing

Contributions to the package are more than welcome — open an Issue or submit a Pull Request. Please run composer test before opening a PR (see CONTRIBUTING.md).

Useful Links


All versions of fuzz with dependencies

PHP Build Version
Package Version
Requires php Version ^8.4
laravel/serializable-closure Version ^2.0
nikic/php-fuzzer Version ^0.0.11
pestphp/pest-plugin Version ^5.0.0
symfony/process Version ^7.0|^8.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package jonpurvis/fuzz contains the following files

Loading the files please wait ...