PHP Development

Installing Composer and Using It to Manage PHP Libraries: A Comprehensive Guide

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (7 sections)

Composer is the dependency manager for PHP: you list the libraries your project needs, and Composer downloads the right versions, their own dependencies and an autoloader that loads them for you. This guide installs Composer 2 on your computer or your own VPS, covers the everyday commands, and shows how to deploy a Composer project to shared hosting, where Composer isn't pre-installed but can be run over jailed SSH.

Key takeaways

Install Composer 2 on your own computer (the Windows installer, Homebrew on macOS, or the verified installer script on Linux) or on a VPS. Use composer require to add libraries, commit composer.json and composer.lock, and include vendor/autoload.php in your code. On Domain India shared hosting Composer isn't pre-installed: with jailed SSH (on request) download composer.phar and run php composer.phar install --no-dev --optimize-autoloader, adding --no-scripts if it stops with a proc_open message, or run that install on your computer, matched to the server's PHP version, and upload the project with its vendor/ folder.

Composer on shared hosting

Composer isn't pre-installed on shared hosting, but with jailed SSH (on request) you can download composer.phar and run php composer.phar install. Shared hosting disables PHP functions such as proc_open that Composer scripts need, so if the install stops with a proc_open message, run it again with --no-scripts. This is a security setting, not a fault with your account. Or build on your computer or in CI and upload the result. See PHP disabled functions on shared hosting.

1. What Composer does

Three files and folders do all the work:

File or folderWhat it isCommit to Git?
composer.jsonThe libraries you asked for and their allowed versionsYes
composer.lockThe exact versions installed, so every machine gets the sameYes, for applications
vendor/The downloaded libraries and the autoloaderNo; rebuild it from the lock file

Version constraints use ^ most of the time: "guzzlehttp/guzzle": "^7.9" allows any 7.x from 7.9 up, but never 8.0, which may break your code.

2. Install Composer

You need PHP on the command line (php -v) with the openssl and zip extensions; git and unzip help too.

  • Windows: download and run Composer-Setup.exe from getcomposer.org. It finds your PHP and adds composer to your PATH.
  • macOS: brew install composer.
  • Linux or your VPS: use the official installer and check its signature before running it:
bash
php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');"
EXPECTED="$(curl -fsSL https://composer.github.io/installer.sig)"
ACTUAL="$(php -r "echo hash_file('sha384', 'composer-setup.php');")"
[ "$EXPECTED" = "$ACTUAL" ] && echo "Installer verified" || { echo "Installer corrupt"; rm composer-setup.php; exit 1; }
sudo php composer-setup.php --install-dir=/usr/local/bin --filename=composer
rm composer-setup.php
composer --version

Distribution packages (apt install composer, dnf install composer) also work but are often a version behind; composer self-update keeps the installer version current. Don't run Composer as root on a project; use your normal user.

3. Everyday commands

bash
composer init                               # create composer.json interactively
composer require guzzlehttp/guzzle          # add a library
composer require --dev phpunit/phpunit      # add a development-only tool
composer install                            # install exactly what composer.lock says
composer update vendor/package              # update one library within its constraint
composer remove vendor/package              # remove a library
composer outdated --direct                  # what has newer versions
composer audit                              # known security advisories in your dependencies

Then load everything with one line at the top of your entry script:

php
<?php
require __DIR__ . '/vendor/autoload.php';

Use install for deployments and update only when you mean to change versions, then test and commit the new composer.lock. Running update blindly on a live project is how sites break.

Your own classes can use the same autoloader. Add a PSR-4 mapping to composer.json and run composer dump-autoload:

json
{
    "autoload": {
        "psr-4": { "App\\": "src/" }
    }
}

4. Deploy a Composer project to shared hosting

The simplest route is to build the vendor/ folder on your computer. The one thing to get right is the PHP version.

  1. Check the server's PHP version.
    In cPanel open MultiPHP Manager (or your panel's PHP version page) and note the version your domain uses.
  2. Tell Composer to build for that version.
    Run composer config platform.php 8.3.0, using your server's version, then composer update once so the lock file is resolved for it. Composer then picks library versions that will run there, even if your computer has newer PHP.
  3. Build for production.
    Run composer install --no-dev --optimize-autoloader. This leaves out development tools and speeds up autoloading.
  4. Upload the project with vendor/.
    Zip the project, upload it with File Manager or SFTP, and extract it. Keep vendor/, .env and your source outside public_html where you can, with only the public folder in the web root.
  5. Repeat after every dependency change.
    When composer.lock changes, rebuild and upload vendor/ again.
cPanel MultiPHP Manager showing the system PHP version, a PHP Version dropdown with Apply, and a domain row with a checkbox and its current version
Note your domain's PHP version in MultiPHP Manager before building.

Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. On our cPanel servers git is available inside the jail, so you can pull your code with Git and build vendor/ there: download Composer with curl -sS -o composer.phar https://getcomposer.org/download/latest-stable/composer.phar and run php composer.phar install --no-dev --optimize-autoloader. If it stops with a proc_open message, run it again with --no-scripts and run the commands under scripts in composer.json yourself with php. For a full framework example, see Deploying Laravel on cPanel.

5. Libraries worth knowing

guzzlehttp/guzzle
HTTP client for calling APIs. Set a timeout on every request so a slow API can't hold your pages.
phpmailer/phpmailer
Builds proper emails with attachments and HTML. On our cPanel servers, send through mail() rather than SMTP (see below).
vlucas/phpdotenv
Loads settings and secrets from a .env file, so they stay out of your code.
ezyang/htmlpurifier
Cleans user-submitted HTML to prevent XSS.
intervention/image
Resizes and crops images; needs the GD or Imagick extension.
endroid/qr-code
Generates QR codes as PNG or SVG.

Sending mail with PHPMailer on cPanel: SMTP fails on our cPanel servers because the socket functions it needs are disabled. PHPMailer's isMail() mode with Sender is no fix either: PHPMailer passes the envelope sender (-f) only when escapeshellcmd is available, and it is disabled there, so Sender is silently ignored and the Return-Path becomes the server's address. Instead, let PHPMailer build the message with preSend(), then send it yourself with PHP mail() and -f:

php
$from = '[email protected]';           // a mailbox on your own domain
$mail->isMail();
$mail->setFrom($from, 'Your Site');
$mail->addAddress($to);
// ... Subject, Body, attachments ...
$mail->preSend();                           // build the message, don't send it

// Split headers from body, take out To and Subject, then send with -f.
[$head, $body] = preg_split("/\r?\n\r?\n/", $mail->getSentMIMEMessage(), 2);
$head = preg_replace("/\r?\n[ \t]+/", ' ', $head);
$headers = [];
$subject = '';
foreach (preg_split("/\r?\n/", $head) as $line) {
    if (stripos($line, 'To:') === 0) { continue; }
    if (stripos($line, 'Subject:') === 0) { $subject = trim(substr($line, 8)); continue; }
    $headers[] = $line;
}
mail($to, $subject, $body, implode("\r\n", $headers), '-f' . $from);

The complete handler, with validation and error handling, is in How to use PHPMailer for contact forms.

On DirectAdmin we haven't measured the socket functions, so test SMTP on your plan. See PHP sendmail settings.

Keep debugging tools such as filp/whoops in require-dev only; an error page that shows code and settings must never reach a live site.

6. Troubleshooting

MessageCauseFix
proc_open() has been disabled for security reasonsA Composer script (or --prefer-source) tried to start a program on shared hostingRun it again with --no-scripts, then run the script commands yourself with php, or build vendor/ on your computer and upload it
The Process class relies on proc_open, which is not available on your PHP installationA Composer script needs proc_open, which is disabled on shared hostingRun it again with --no-scripts, then run the script commands yourself with php
Your requirements could not be resolvedA library needs a different PHP version or extensionSet platform.php to the server's version, or choose another library version
Composer detected issues in your platformvendor/ was built for newer PHP than the server runsRebuild with platform.php set correctly and upload again
Allowed memory size exhaustedDependency resolution on a large projectRun COMPOSER_MEMORY_LIMIT=-1 composer update on your computer
The zip extension and unzip command are both missingMissing PHP extensionInstall php-zip or unzip on your computer or VPS

7. Where Domain India fits

Shared hosting runs Composer-built PHP projects well once you upload vendor/.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

A VPS gives you root access, so you can install Composer on the server, run it in your deployment script and use any PHP extension. It is self-managed.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Prices on the cards are live and exclude 18% GST. The App Platform detects Node.js apps automatically; a PHP app there needs its own Dockerfile.

Can I run Composer on Domain India shared hosting?

Yes, over jailed SSH (on request). Composer isn't pre-installed, so download composer.phar and run php composer.phar install; if it stops with a proc_open message, run it again with --no-scripts. Or run Composer on your computer or in CI and upload the project with its vendor folder.

Should I upload the vendor folder?

Yes, on shared hosting, unless you build it there over SSH with composer.phar. Upload the vendor folder you built with composer install --no-dev --optimize-autoloader. In Git you normally leave vendor out and rebuild it from composer.lock.

How do I make sure vendor works with the server's PHP version?

Check the version your domain uses in the control panel, run composer config platform.php with that version, then run composer update once and build with composer install. Composer then chooses library versions that run on the server.

What is the difference between composer install and composer update?

composer install installs exactly the versions recorded in composer.lock. composer update looks for newer versions within your constraints and rewrites composer.lock. Use install for deployments and update only when you intend to change versions.

Why does PHPMailer fail with SMTP on cPanel hosting?

The PHP socket functions SMTP needs are disabled on our cPanel servers, and PHPMailer's isMail() mode silently ignores the Sender address there because escapeshellcmd is disabled. Let PHPMailer build the message with preSend(), then send it with PHP mail() and -f set to an address on your own domain, as shown in How to use PHPMailer for contact forms.

Can I install Composer on a Domain India VPS?

Yes. The VPS gives you root access, so install Composer with the official installer and run it as a normal user in your project.

Ready to deploy your PHP project? Read PHP disabled functions on shared hosting, compare cPanel hosting and VPS plans, or open a ticket if you are not sure which fits your project.

Host your PHP project

Choose your PHP version, upload your Composer-built project and get free SSL on every plan.

See cPanel hosting

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Install Composer and Manage PHP Libraries (2026 Guide)