Composer is how modern PHP projects pull in libraries such as Dompdf, PHPMailer or Guzzle. On Domain India cPanel hosting Composer isn't pre-installed, but with jailed SSH (on request) you can download composer.phar and run it with PHP; its scripts need a disabled function, so you may need --no-scripts. The other method is to run Composer on your own computer and upload the finished vendor folder. This guide shows both and gives current, working examples for the most-used libraries.
Install Composer on your computer, set config.platform.php in composer.json to the PHP version your hosting account uses, run composer install --no-dev --optimize-autoloader, then upload your project including vendor/ with File Manager or FTP. In your code, load vendor/autoload.php once. Over jailed SSH you can also run php composer.phar install on the server; proc_open is disabled for every account, so if Composer scripts stop the install, run it again with --no-scripts.
1. Running Composer on the server
Composer isn't pre-installed, but with jailed SSH you can download it into your account and run it with PHP:
curl -sS -o composer.phar https://getcomposer.org/download/latest-stable/composer.phar
php composer.phar install --no-dev --optimize-autoloaderThis downloads and installs normal libraries. Composer scripts (the scripts section of composer.json, such as Laravel's package:discover) need PHP's proc_open to start other programs, and on our cPanel servers proc_open, popen, exec and similar functions are disabled for every account, for the web server and the command line alike. A project with scripts stops with an error like:
The Process class relies on proc_open, which is not available on your PHP installation.This protects every account on the server from a compromised neighbour, and it cannot be switched on for one account. Run the command again with --no-scripts, then run the commands listed under scripts in composer.json yourself with php (for Laravel, php artisan package:discover). Or move the Composer step to your computer, as the next sections show; the code Composer downloads runs fine on the server either way. The full list of disabled functions, and what else they affect, is in PHP disabled functions on shared hosting.
2. Install Composer on your computer
- Windows: download and run
Composer-Setup.exefrom getcomposer.org. It finds your PHP installation and addscomposerto your PATH. - macOS:
brew install composer. - Linux: follow the command-line installer on getcomposer.org, which checks the installer's signature before running it, then move
composer.pharto a folder on your PATH such as~/.local/bin/composer.
Check it works:
composer --version
php --versionYou need PHP on your computer too. Use the same major and minor version as your hosting account if you can.
3. Match your server's PHP version
Libraries publish different releases for different PHP versions. If your computer runs a newer PHP than the server, Composer may pick releases the server cannot run. Tell Composer which version the server has:
- In cPanel, open MultiPHP Manager and note the version your domain uses.
- Add it to
composer.json:
{
"config": {
"platform": {
"php": "8.3.0"
}
}
}Replace 8.3.0 with your server's version. Composer now chooses releases that work there, even if your laptop has a newer PHP.
4. Build and upload your project
- Create or open your project folderon your computer.
- Add librarieswith
composer require vendor/package, for examplecomposer require dompdf/dompdf. - Build for productionwith
composer install --no-dev --optimize-autoloader. This skips test tools and makes class loading faster. - Upload the whole project, including
vendor/,to your account. Zip it, upload the zip with cPanel File Manager and extract it there; or upload with FTP over TLS (or SFTP, if SSH is enabled on your account). - Keep
vendor/outsidepublic_htmlif you can.Put the project in a folder besidepublic_htmland require the autoloader by path, so library files cannot be opened in a browser. - Testby opening your page. A white screen usually means a missing file or a PHP version mismatch; check the error log in cPanel.
To update a library later, run composer update vendor/package on your computer, rebuild, and upload vendor/ and composer.lock again.
The vendor folder can hold thousands of small files, which is slow over FTP. Zip it on your computer, upload one file with File Manager, and extract it on the server.
5. Load libraries in your code
Every example below starts by loading Composer's autoloader once:
<?php
require __DIR__ . '/vendor/autoload.php';If vendor/ sits outside public_html, adjust the path, for example require __DIR__ . '/../myapp/vendor/autoload.php';.
6. Popular libraries that work on shared hosting
| Library | Package | Use it for | Shared hosting notes |
|---|---|---|---|
| Dompdf | dompdf/dompdf | HTML to PDF | Pure PHP, works |
| mPDF | mpdf/mpdf | HTML to PDF with good Unicode support | Pure PHP, works |
| PHPMailer | phpmailer/phpmailer | Sending email | Build with preSend(), send with mail() and -f; SMTP and isMail() Sender don't work on cPanel |
| Guzzle | guzzlehttp/guzzle | Calling HTTP APIs | Normal (synchronous) requests work; avoid async and concurrent requests |
| Carbon | nesbot/carbon | Dates and times | Pure PHP, works |
| Monolog | monolog/monolog | Logging to files | Write logs outside public_html |
| Intervention Image | intervention/image | Resize and edit images | Use the GD driver |
| Faker | fakerphp/faker | Test data | Development only; install with --dev |
| PHPUnit | phpunit/phpunit | Unit tests | Run on your computer, not the server |
A few current examples:
Dompdf: create a PDF
use Dompdf\Dompdf;
$dompdf = new Dompdf();
$dompdf->loadHtml('<h1>Invoice 1001</h1>');
$dompdf->setPaper('A4', 'portrait');
$dompdf->render();
$dompdf->stream('invoice-1001.pdf');PHPMailer: build the message, send it with mail() and -f
On our cPanel servers, PHPMailer's own isMail() mode sends, but it silently ignores Sender: PHPMailer passes the envelope sender (-f) only when the PHP function escapeshellcmd is available, and it is disabled there. Without -f, the Return-Path is the server's address and SPF no longer lines up with your domain. So let PHPMailer build the message with preSend(), then send it yourself with PHP mail() and -f:
use PHPMailer\PHPMailer\PHPMailer;
use PHPMailer\PHPMailer\Exception;
$from = '[email protected]'; // a mailbox on your own domain
$to = '[email protected]';
$mail = new PHPMailer(true);
try {
$mail->isMail();
$mail->CharSet = 'UTF-8';
$mail->setFrom($from, 'Your Shop');
$mail->addAddress($to);
$mail->Subject = 'Your order';
$mail->Body = 'Thank you for your order.';
$mail->preSend(); // build the message, don't send it
// Split the built message into headers and body; mail() adds To and Subject itself.
[$head, $body] = preg_split("/\r?\n\r?\n/", $mail->getSentMIMEMessage(), 2);
$head = preg_replace("/\r?\n[ \t]+/", ' ', $head); // unfold long headers
$headers = [];
$subject = '';
foreach (preg_split("/\r?\n/", $head) as $line) {
if (stripos($line, 'To:') === 0) { continue; }
if (stripos($line, 'Subject:') === 0) { $subject = trim(substr($line, 8)); continue; }
$headers[] = $line;
}
if (!mail($to, $subject, $body, implode("\r\n", $headers), '-f' . $from)) {
error_log('Mail failed: mail() returned false');
}
} catch (Exception $e) {
error_log('Mail failed: ' . $mail->ErrorInfo);
}Use a sender address on your own domain, and set up SPF and DKIM for it. For a complete contact-form handler with validation and Reply-To, see How to use PHPMailer for contact forms; for SPF, DKIM and DMARC, see PHP sendmail settings.
Guzzle: call an API
use GuzzleHttp\Client;
$client = new Client(['timeout' => 10]);
$response = $client->get('https://api.example.com/status');
echo $response->getBody();Always set a timeout. A request that hangs holds a PHP worker until it finishes.
Intervention Image (version 3): resize a photo
use Intervention\Image\ImageManager;
$manager = ImageManager::gd();
$image = $manager->read('uploads/photo.jpg');
$image->scale(width: 800);
$image->save('uploads/photo-800.jpg');The old Image::make() syntax belongs to version 2. If a tutorial uses it, it is out of date.
7. Frameworks and Laravel
Frameworks such as Laravel and Slim work the same way: build locally and upload with vendor/, or run Composer over SSH with --no-scripts and then the framework's script commands with php. Framework setup commands that run PHP from the command line (for example generating an application key) also run on your computer before you upload. For the full Laravel route, including .env, the document root and the database, see Deploying Laravel on cPanel or How to install Laravel using Softaculous.
8. Running this on Domain India
Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. Login is by SSH key. SSH is useful for unzipping uploads, reading logs and running php composer.phar as described in section 1; the same disabled functions apply on the command line, which is why Composer scripts may need --no-scripts. See jailed SSH on Domain India hosting.
If your project really needs Composer scripts, background workers or programs started from PHP on the server, use a server you control:
- a VPS, self-managed with full root access, where Composer runs normally;
- the App Platform, where PHP apps run from a Dockerfile you provide, so
composer installcan run as a step in your own build.
For ordinary PHP sites that use libraries, cPanel hosting is enough. The card shows the live price, excluding 18% GST:
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
Can I run Composer on Domain India cPanel hosting?
Yes, over jailed SSH (on request). Composer isn't pre-installed, so download composer.phar and run php composer.phar install. Composer scripts need proc_open, which is disabled for every account, so if it stops with a proc_open message, run it again with --no-scripts. Or run Composer on your own computer and upload the project with its vendor folder.
Do the libraries still work if I install them on my computer?
Yes. Composer only downloads the library code. Once the vendor folder is uploaded, the libraries run on the server like any other PHP code, as long as they do not need a disabled function.
How do I make sure the libraries match the server's PHP version?
Check your PHP version in cPanel, then set config.platform.php in composer.json to that version before running composer install. Composer will then choose releases that run on the server.
Why does PHPMailer fail with SMTP on shared hosting?
SMTP needs PHP socket functions that are disabled on our cPanel servers. PHPMailer's isMail() mode with Sender does not help either: the Sender is silently ignored there because escapeshellcmd is disabled. Let PHPMailer build the message with preSend(), then send it with PHP mail() and -f set to an address on your own domain, as shown in How to use PHPMailer for contact forms.
Can support enable proc_open for my account?
No. It is a server-wide security setting that cannot be enabled for a single account. If your application needs it, use a VPS or the App Platform.
Where should I put the vendor folder?
Preferably in a project folder outside public_html, with your public PHP files requiring the autoloader by path. That stops visitors from opening library files directly.
Ready to build your project? Read PHP disabled functions on shared hosting first, then compare cPanel hosting, VPS and App Platform plans.
Tell us the package name and the error you see, and we will tell you whether it can run on shared hosting.
Open a support ticket