The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Phpray listing page.
Every PHP request, recorded. Find out which plugin, which query, and since when.
PHPRay is always-on request tracing for PHP. It records wall time, CPU, memory, SQL, outbound HTTP, errors and N+1 patterns for every request, not a sample, and on a small share of requests it adds a per-plugin / per-component time breakdown. One site or a hundred client sites: the same install, and one list for all of them.
It is a PHP extension plus a local collector. No agent that needs root, no network egress from the PHP process, no SaaS account required. It runs on shared hosting (CageFS, LiteSpeed lsphp, mod_php), on a VPS and in containers, on PHP 8.0–8.5, glibc and musl, amd64 and arm64.
After a few minutes of traffic, phpray report --domain example.com --share
prints a link you can send to a client: the site name is removed, the link
expires, and the recipient needs nothing installed to read it.
Rather look before installing anything? Three ways in, none of them needing root, an account or a card:
claude mcp add --transport http phpray https://phpray.dev/mcp
answers from the same demo data with no key (details).

PHPRay Cloud: every site, then one site, then one 887 ms request broken into PHP and database time, the plugins that spent it, and the queries behind it. Demo data.
"The store got slow last week" is not actionable. PHPRay turns it into a named plugin, a named query and the day it changed:

Most of what is written above is about one server. The harder job is the other one: forty sites you did not build, on hosting you did not choose, and a client asking why checkout is slow today.
php.ini, or the
WordPress plugin runs with neither
an extension nor a daemon. Never enable the extension for a whole PHP version on a
shared server — install it per account.phpray report -domain shop.example -share
publishes the findings and prints a link. The site name is stripped, the address
expires and is not indexed. No account, no card.The local core stays Apache-2.0 and has no limits: as many sites, servers and requests as you like, data on your own disk. What costs money is the hosted console that puts those sites in one list — priced by how many sites you keep in it, starting with one site free. Prices are on phpray.dev/en/pricing.
phpray.profile_functions=0 if you want the cheapest possible
always-on layer and turn the breakdown on only when investigating.php.ini — cPanel
MultiPHP INI Editor, CloudLinux PHP Selector, Plesk — you can point extension= at a
.so in your home directory and run the collector as your own user. No root, no
compiler, nobody's permission. Verified end to end as uid 1000; the cases where it
does not work are listed in
the docs.Built by IQhost, a European hosting provider running PHP for thousands of sites. That is where PHPRay is developed and where it is deployed first: the shared-hosting constraints in this README are not hypothetical, they are the environment the extension has to survive in every day.
PHPRay ships an MCP server, so a coding agent can read your traces and answer "which plugin is slowing this page down" without you opening a dashboard.
Try it with nothing installed and no account — you get a read-only demo account with a real WooCommerce store's recorded traffic:
Then ask: which pages are slowest, which SQL fingerprint costs the most, which
plugin eats the time. Add --header "Authorization: Bearer <console token>"
and the same tools read your own sites instead.
Or run it locally as a binary over stdio:
In cloud mode the token is your console token, so the agent sees exactly the sites it is scoped to. In local mode it reads the collector on the same box and needs no account at all.
Ten read-only tools — sites, overview, slowest pages, slow SQL, component
breakdown, errors, traces, one trace in full, before/after comparison, alerts —
plus an eleventh, phpray_profile_url, which turns per-function profiling on
for a URL prefix. That one changes state, so the public demo endpoint does
not offer it: without a token tools/list returns ten. With your own console
token, or locally over stdio, you get all eleven. Source and protocol notes:
src/mcp/.
Everything in this repository is free and open source under Apache-2.0: the extension, the collector, the CLI, the local dashboard and the panel plugins. It is a complete product on its own, on one server, forever.
PHPRay Cloud is the paid part: many servers in one place, history beyond your disk, alerting and the hosting-panel console. It is a separate, closed codebase. Nothing here phones home to it unless you configure a server key yourself.
Piping an installer straight into a root shell is a habit worth not having, ours
included: download it, read it, then run it. The checksums of everything it
fetches are published next to the files, under
https://phpray.dev/dl/<version>/SHA256SUMS, and the installer verifies them.
The installer detects every PHP version on the host, installs the prebuilt phpray.so for each of them, deploys the collector with its systemd unit, and reloads the PHP pools. It is a single binary with zero external dependencies.
If you prefer to place the pieces yourself:
The one PHPRay artefact regularly read by people who never installed it: an agency sends it to the shop owner, an administrator pastes it into a ticket.
One self-contained file — no external requests, no fonts, no scripts — with the
health score, what was found, what it costs and what to do about it. With
-anonymize the domain is replaced everywhere, including inside the findings and
the evidence, so the same report can go on a forum or into a proposal.
People share links, not attachments, so the same findings can be published as a page:
No account and no card — this works from the collector in this repository.
What leaves the server is the findings data, never a document: the page is
rendered from it by our template. The site name is stripped from every text
field, evidence lines included, so shop.example/checkout/ is published as
/checkout/. The address carries 128 bits of randomness, expires after 30
days and is not indexed. -share-url points the same command at your own
copy of the console.
Every request produces one JSON record. A request that has also been function-profiled carries "profiled": 1 and a components array with incl_ns, self_ns and calls per component:
incl_ns is the time spent inside a component (including any core or other PHP it calls); self_ns excludes nested components; calls is the number of observed function calls in that component.
The six directives you are most likely to touch. PERDIR means it can be overridden per site or directory; SYSTEM means it must be set in php.ini.
The remaining directives (smart-sampling thresholds, ignored URIs, ring-buffer size, header emission, …) are documented in docs/.
Per-site control under Apache (mod_php / LiteSpeed) or with a .user.ini on the right pool:
All hooks (MySQL/curl/file, the error callback and the observer) are installed at MINIT regardless of phpray.enabled, so a single site can be enabled on a globally disabled server; the only way to run without the observer at all is phpray.profile_functions = 0. JSONL records are written with one write() on an O_APPEND descriptor, so concurrent workers never interleave lines.
The always-on tracing layer is designed to add as little as possible on the hot path. The figures are measured on a real WooCommerce test store (Storefront theme, 22 active plugins, PHP 8.3 with OPcache) with and without the extension, never on synthetic scripts; the full methodology — workload, environment, how each number was taken and its margin of error — is in docs/.
Status (September 2026): internal runs on a laptop put the always-on layer within the measurement noise of the bare-PHP baseline, and profiling of every request measurably above it, yet far below what a classic execute_ex hook costs. We do not publish those as product figures. Certified numbers, the methodology and the raw data will follow the benchmark on a dedicated, quiet host.
Both live in their own repositories, because they have their own release cycles and, in WordPress's case, its own licence.
WordPress (GPLv2+). If you
cannot load a PHP extension — hosted shared hosting, PaaS — the plugin is a
pure-PHP collector: it hooks $wpdb, the HTTP API and the error handler, and
sends the same trace format to your local collector or to PHPRay Cloud. You get
the always-on layer (timing, SQL, HTTP, errors, N+1) without the extension, and
the README is explicit about the four things it cannot see.
DirectAdmin (Apache-2.0).
A panel plugin with two views: customers see their own domains, the administrator
sees the whole server. On CloudLinux it can switch the extension on or off per
account, which .user.ini cannot do — PHP reads per-directory values long after
module startup. Customers also get "profile this URL prefix for N minutes" without
SSH.
Host Edition customers and anyone who wants a hosted console can send traces to PHPRay Cloud: multi-domain fleet view, retention and history, alerts, and white-label diagnostic reports for clients. Plans: Free, Solo 19, Studio 99, Agency 249, Fleet 499 USD per month; Host Edition is billed yearly. See https://phpray.dev/pricing. The PHP extension and the local collector remain free and open source — the cloud is an optional destination, not a dependency.
We use the Developer Certificate of Origin (DCO). Sign off each commit with git commit -s. Open an issue before large changes.
To report a security issue, email security@phpray.dev (PGP on the website). Please do not open a public issue.
Apache License, Version 2.0 — see LICENSE.
"PHPRay" is a trademark of IQhost. The extension, the collector, and this repository are licensed as stated above; the trademark is not granted.
Built by IQhost — a European hosting provider running PHP for thousands of sites, which is where PHPRay is developed and first deployed.