PHP Development

A Comprehensive Guide to Composer: PHP Dependency Management with a Practical Example

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (5 sections)

Composer is the dependency manager for PHP. You list the libraries your project needs in composer.json, and Composer downloads the right versions, their own dependencies and an autoloader that loads every class for you. This page gives a short practical example; the full guide covers installation, everyday commands and deployment in depth.

For the full guide

Our complete, current guide is Installing Composer and using it to manage PHP libraries. For library examples on cPanel hosting (Dompdf, PHPMailer, Guzzle), see Installing PHP libraries using Composer on cPanel hosting.

Key takeaways

Install Composer 2 on your own computer, in CI or on a VPS, then use composer require to add libraries and include vendor/autoload.php once in your code. Commit composer.json and composer.lock, not vendor/. Composer cannot run on Domain India shared hosting, so build with composer install --no-dev --optimize-autoloader on your computer or in CI and upload the project with its vendor/ folder, or use a VPS or the App Platform.

Composer does not run on shared hosting

Shared hosting disables PHP functions such as proc_open that Composer needs, on the command line as well as the web, so composer install fails on the server even with --prefer-dist --no-scripts, and even over SSH. Build locally or in CI and upload vendor/. See PHP disabled functions on shared hosting.

1. What Composer manages

File or folderWhat it isCommit to Git?
composer.jsonThe libraries you asked for and their allowed versionsYes
composer.lockThe exact versions installed, so every machine gets the sameYes, for applications
vendor/The downloaded libraries and the autoloaderNo; rebuild it from the lock file

Version constraints usually use ^: "twig/twig": "^3.0" allows any 3.x release from 3.0 up, but never 4.0, which may break your code.

2. Install Composer

  • Windows: run Composer-Setup.exe from getcomposer.org.
  • macOS: brew install composer.
  • Linux or your own VPS: use the official installer from getcomposer.org and check its signature before running it. The full guide has the exact commands.

Check it works with composer --version. Don't run Composer as root inside a project; use your normal user.

3. A practical example: a small project with autoloading

This builds a tiny project that renders a page with the Twig template engine and loads your own classes through Composer's autoloader.

  1. Create the project.
    Make a folder simple-site and run composer init inside it, or create composer.json by hand as shown below.
  2. Add a library.
    Run composer require twig/twig. Composer downloads Twig, writes the version to composer.json and records the exact release in composer.lock.
  3. Map your own classes.
    Add the autoload section shown below, put your classes in src/, and run composer dump-autoload.
  4. Load everything once.
    Your entry script needs a single require of vendor/autoload.php.
  5. Build for production.
    Run composer install --no-dev --optimize-autoloader before you deploy.
json
{
    "name": "example/simple-site",
    "require": {
        "php": ">=8.2",
        "twig/twig": "^3.0"
    },
    "autoload": {
        "psr-4": { "App\\": "src/" }
    }
}

src/Greeting.php:

php
<?php
namespace App;

final class Greeting
{
    public function for(string $name): string
    {
        return 'Hello, ' . $name;
    }
}

public/index.php:

php
<?php
require __DIR__ . '/../vendor/autoload.php';

use App\Greeting;
use Twig\Environment;
use Twig\Loader\ArrayLoader;

$twig = new Environment(new ArrayLoader([
    'page' => '<h1>{{ message }}</h1>',
]));

echo $twig->render('page', ['message' => (new Greeting())->for('Domain India')]);

Twig escapes {{ message }} for HTML by default, so user input shown this way is safe from basic XSS.

4. Everyday commands

bash
composer require vendor/package        # add a library
composer require --dev phpunit/phpunit # development-only tool
composer install                       # install exactly what composer.lock says
composer update vendor/package         # update one library within its constraint
composer outdated --direct             # which libraries have newer versions
composer audit                         # known security advisories

Use install for deployments and update only when you mean to change versions; then test and commit the new composer.lock.

5. Deploy to Domain India hosting

Shared hosting (cPanel, DirectAdmin, Webuzo): Composer cannot run on the server, so the vendor/ folder comes from your computer or CI.

  1. Check your site's PHP version in the control panel.
  2. Run composer config platform.php 8.3.0 with that version, then composer update once, so Composer picks releases that run on the server.
  3. Build with composer install --no-dev --optimize-autoloader.
  4. Zip the project, upload it with File Manager or FTP, and extract it. Keep vendor/ and src/ outside public_html where you can, with only the public folder in the web root.

Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. It helps with unzipping and reading logs, but it does not make Composer work.

VPS: self-managed with root access, so Composer runs normally in your deployment script.

App Platform: a PHP app needs its own Dockerfile, where composer install runs as a build step.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

The card shows the live price, excluding 18% GST.

What is Composer used for in PHP?

Composer manages a PHP project's libraries. You list what you need in composer.json, and Composer downloads matching versions with their own dependencies, records the exact versions in composer.lock and generates an autoloader in vendor/autoload.php.

Can I run Composer on Domain India shared hosting?

No. Shared hosting disables PHP functions such as proc_open that Composer needs, on the web and the command line, so composer install fails on the server even over SSH. Run Composer on your computer or in CI and upload the project with its vendor folder.

Should I commit the vendor folder to Git?

Normally no. Commit composer.json and composer.lock and rebuild vendor with composer install. On shared hosting you still upload the vendor folder you built, because the server cannot build it.

What is the difference between composer install and composer update?

composer install installs exactly the versions in composer.lock. composer update looks for newer versions within your constraints and rewrites composer.lock. Use install for deployments.

How do I make vendor match the server's PHP version?

Check the PHP version your site uses in the control panel, run composer config platform.php with that version, run composer update once, then build with composer install --no-dev --optimize-autoloader.

Ready to go further? Read the full Composer guide, check PHP disabled functions on shared hosting, or compare cPanel hosting, VPS and the App Platform.

Host your PHP project

Choose your PHP version, upload your Composer-built project and get free SSL on every plan.

See cPanel hosting

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Composer for PHP: A Practical Guide with Example