Composer is the dependency manager for PHP. You list the libraries your project needs in composer.json, and Composer downloads the right versions, their own dependencies and an autoloader that loads every class for you. This page gives a short practical example; the full guide covers installation, everyday commands and deployment in depth.
Our complete, current guide is Installing Composer and using it to manage PHP libraries. For library examples on cPanel hosting (Dompdf, PHPMailer, Guzzle), see Installing PHP libraries using Composer on cPanel hosting.
Install Composer 2 on your own computer, in CI or on a VPS, then use composer require to add libraries and include vendor/autoload.php once in your code. Commit composer.json and composer.lock, not vendor/. Composer cannot run on Domain India shared hosting, so build with composer install --no-dev --optimize-autoloader on your computer or in CI and upload the project with its vendor/ folder, or use a VPS or the App Platform.
Shared hosting disables PHP functions such as proc_open that Composer needs, on the command line as well as the web, so composer install fails on the server even with --prefer-dist --no-scripts, and even over SSH. Build locally or in CI and upload vendor/. See PHP disabled functions on shared hosting.
1. What Composer manages
| File or folder | What it is | Commit to Git? |
|---|---|---|
| composer.json | The libraries you asked for and their allowed versions | Yes |
| composer.lock | The exact versions installed, so every machine gets the same | Yes, for applications |
| vendor/ | The downloaded libraries and the autoloader | No; rebuild it from the lock file |
Version constraints usually use ^: "twig/twig": "^3.0" allows any 3.x release from 3.0 up, but never 4.0, which may break your code.
2. Install Composer
- Windows: run Composer-Setup.exe from getcomposer.org.
- macOS:
brew install composer. - Linux or your own VPS: use the official installer from getcomposer.org and check its signature before running it. The full guide has the exact commands.
Check it works with composer --version. Don't run Composer as root inside a project; use your normal user.
3. A practical example: a small project with autoloading
This builds a tiny project that renders a page with the Twig template engine and loads your own classes through Composer's autoloader.
- Create the project.Make a folder
simple-siteand runcomposer initinside it, or createcomposer.jsonby hand as shown below. - Add a library.Run
composer require twig/twig. Composer downloads Twig, writes the version tocomposer.jsonand records the exact release incomposer.lock. - Map your own classes.Add the
autoloadsection shown below, put your classes insrc/, and runcomposer dump-autoload. - Load everything once.Your entry script needs a single
requireofvendor/autoload.php. - Build for production.Run
composer install --no-dev --optimize-autoloaderbefore you deploy.
{
"name": "example/simple-site",
"require": {
"php": ">=8.2",
"twig/twig": "^3.0"
},
"autoload": {
"psr-4": { "App\\": "src/" }
}
}src/Greeting.php:
<?php
namespace App;
final class Greeting
{
public function for(string $name): string
{
return 'Hello, ' . $name;
}
}public/index.php:
<?php
require __DIR__ . '/../vendor/autoload.php';
use App\Greeting;
use Twig\Environment;
use Twig\Loader\ArrayLoader;
$twig = new Environment(new ArrayLoader([
'page' => '<h1>{{ message }}</h1>',
]));
echo $twig->render('page', ['message' => (new Greeting())->for('Domain India')]);Twig escapes {{ message }} for HTML by default, so user input shown this way is safe from basic XSS.
4. Everyday commands
composer require vendor/package # add a library
composer require --dev phpunit/phpunit # development-only tool
composer install # install exactly what composer.lock says
composer update vendor/package # update one library within its constraint
composer outdated --direct # which libraries have newer versions
composer audit # known security advisoriesUse install for deployments and update only when you mean to change versions; then test and commit the new composer.lock.
5. Deploy to Domain India hosting
Shared hosting (cPanel, DirectAdmin, Webuzo): Composer cannot run on the server, so the vendor/ folder comes from your computer or CI.
- Check your site's PHP version in the control panel.
- Run
composer config platform.php 8.3.0with that version, thencomposer updateonce, so Composer picks releases that run on the server. - Build with
composer install --no-dev --optimize-autoloader. - Zip the project, upload it with File Manager or FTP, and extract it. Keep
vendor/andsrc/outsidepublic_htmlwhere you can, with only thepublicfolder in the web root.
Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. It helps with unzipping and reading logs, but it does not make Composer work.
VPS: self-managed with root access, so Composer runs normally in your deployment script.
App Platform: a PHP app needs its own Dockerfile, where composer install runs as a build step.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
The card shows the live price, excluding 18% GST.
What is Composer used for in PHP?
Composer manages a PHP project's libraries. You list what you need in composer.json, and Composer downloads matching versions with their own dependencies, records the exact versions in composer.lock and generates an autoloader in vendor/autoload.php.
Can I run Composer on Domain India shared hosting?
No. Shared hosting disables PHP functions such as proc_open that Composer needs, on the web and the command line, so composer install fails on the server even over SSH. Run Composer on your computer or in CI and upload the project with its vendor folder.
Should I commit the vendor folder to Git?
Normally no. Commit composer.json and composer.lock and rebuild vendor with composer install. On shared hosting you still upload the vendor folder you built, because the server cannot build it.
What is the difference between composer install and composer update?
composer install installs exactly the versions in composer.lock. composer update looks for newer versions within your constraints and rewrites composer.lock. Use install for deployments.
How do I make vendor match the server's PHP version?
Check the PHP version your site uses in the control panel, run composer config platform.php with that version, run composer update once, then build with composer install --no-dev --optimize-autoloader.
Ready to go further? Read the full Composer guide, check PHP disabled functions on shared hosting, or compare cPanel hosting, VPS and the App Platform.
Choose your PHP version, upload your Composer-built project and get free SSL on every plan.
See cPanel hosting