Glossary of Terms

Mastering Programming Libraries: A Complete Handbook for Modern Development

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (8 sections)

A programming library is a package of ready-made, tested code that you call from your own program, so you don't have to write everything yourself. Almost every modern project depends on dozens of them. This handbook explains what libraries are, how they differ from frameworks, how to choose and manage them safely in 2026, and how to run a project with dependencies on Domain India hosting.

Key takeaways

A library is code you call; a framework is code that calls you. Choose libraries that are actively maintained, well documented, compatibly licensed and free of known vulnerabilities. Install them with your language's package manager, commit the lock file, audit dependencies regularly and remove the ones you no longer use. On Domain India shared hosting, Composer isn't pre-installed, so run composer.phar over jailed SSH or build PHP projects locally and upload vendor/; Node.js and Python apps install their dependencies through the control panel's app tools.

1. What a library is

A library gives you functions, classes or components for one job: making HTTP requests, parsing dates, validating input, drawing charts, sending email. You decide when to call it and what to do with the result. Good libraries are:

  • Focused: they do one thing well, so you can add or replace them without rewriting your app.
  • Reusable: the same code works across many projects.
  • Documented: a clear API and examples.
  • Maintained: bugs and security issues are fixed in new releases.

2. Library or framework?

QuestionLibraryFramework
Who is in controlYour code calls the libraryThe framework calls your code
ScopeOne taskThe structure of the whole app
Swapping it outUsually easyUsually a rewrite
ExamplesAxios, date-fns, Pandas, Guzzle, DapperLaravel, Django, Spring Boot, Angular, Next.js

Some tools sit in between. React calls itself a library for building user interfaces, but most React apps are built with a framework such as Next.js around it. Vue describes itself as a progressive framework. The label matters less than the question: does this tool decide the shape of my app?

3. Common libraries by language (2026)

JavaScript and TypeScript
React for UI; Zod for validation; date-fns or Luxon for dates; Axios or the built-in fetch for HTTP; Chart.js or D3 for charts.
Python
Requests or HTTPX for HTTP; pandas or Polars and NumPy for data; PyTorch or scikit-learn for machine learning; Pydantic for validation.
PHP
Guzzle for HTTP; Carbon for dates; PHPMailer or Symfony Mailer for email; Monolog for logging.
Java
Jackson for JSON; SLF4J with Logback or Log4j 2 for logging; Hibernate for database access; Apache Commons for utilities.
C# and .NET
System.Text.Json or Json.NET for JSON; Dapper for fast database access; Serilog for logging; Polly for retries.
Real-time and graphics
Socket.IO for real-time messaging; Three.js for 3D in the browser; OpenCV for computer vision.

Some once-standard libraries now have better options. Moment.js is in maintenance mode, and its own team recommends alternatives such as date-fns or Luxon for new projects. jQuery is rarely needed in new code, because modern browsers have querySelector and fetch built in. Lodash is still fine, but many of its helpers now exist in plain JavaScript.

4. How to choose a library

  1. Check that it is alive.
    Look at the date of the latest release, how quickly issues get answers and whether more than one person maintains it.
  2. Read the documentation first.
    If you cannot work out how to use it in ten minutes, your team will struggle too.
  3. Check the licence.
    MIT, BSD and Apache 2.0 are easy to use in commercial work. GPL and AGPL have conditions you must understand before you ship.
  4. Check for known vulnerabilities.
    Search the package in the GitHub Advisory Database or your package manager's audit tool.
  5. Weigh the size and dependencies.
    A small helper that pulls in fifty packages adds risk and, in front-end code, download size.
  6. Confirm it supports your versions.
    Check the language and runtime versions it requires against the ones your hosting offers.

5. Installing and managing libraries

LanguagePackage managerLock fileAudit command
JavaScriptnpm, pnpm, Yarn or Bunpackage-lock.json, pnpm-lock.yaml, yarn.lock, bun.locknpm audit
Pythonpip or uvrequirements.txt with pinned versions, uv.lockpip-audit
PHPComposercomposer.lockcomposer audit
JavaMaven or GradleGradle lock filesOWASP Dependency-Check
C# and .NETNuGetpackages.lock.jsondotnet list package --vulnerable

Good habits for every language:

  • Commit the lock file. It records the exact version of every package, so every install and every server gets the same code.
  • Understand version ranges. Most ecosystems use semantic versioning: ^2.3.0 accepts any 2.x release from 2.3.0, but not 3.0. A major version change can break your code, so upgrade it on purpose and test.
  • Keep production installs lean. Install only runtime dependencies on the server, for example npm ci --omit=dev or composer install --no-dev.
  • Use a virtual environment for Python, so each project has its own packages.
  • Remove what you don't use. Every dependency is code you are trusting.

For hands-on guides, see JavaScript package managers: npm, Yarn, pnpm and Bun and installing Composer and managing PHP libraries.

6. Security and the software supply chain

Libraries are a common way in for attackers, because one popular package runs inside thousands of apps.

  • Log4Shell (2021) was a flaw in the Java logging library Log4j 2 that let attackers run code on servers simply by getting a crafted string logged. Many teams did not know they used Log4j until they searched for it.
  • The xz Utils backdoor (2024) was slipped into a compression library by a contributor who had gained the maintainers' trust over years, and was caught shortly before it reached stable Linux releases.
  • Typosquatting packages with names one letter away from popular ones, and hijacked maintainer accounts, regularly push malicious versions to npm and PyPI.
Treat every dependency as code you run

Pin versions with a lock file, run your package manager's audit command in CI, turn on automated update alerts such as Dependabot or Renovate, and check the exact package name before you install. Update vulnerable packages promptly rather than waiting for the next big release.

7. When libraries cause problems

  • Version conflicts: two packages need different versions of the same dependency. Read the package manager's error, upgrade the older package, or look for a maintained alternative.
  • Bloat: a large library used for one function slows builds and pages. Import only what you need, or use the built-in language feature.
  • Abandoned packages: if a library stops getting updates, plan a replacement before a vulnerability forces one.
  • Debugging inside a library: reproduce the problem in a small script, read the library's changelog and issue tracker, and check whether your version is current before reporting a bug.

8. Running projects with libraries on Domain India

  • PHP on shared hosting: Composer isn't pre-installed, but over jailed SSH you can run php composer.phar install --no-dev; if it stops with a proc_open message, run it again with --no-scripts. Or run composer install --no-dev on your own computer or in CI and upload the project with its vendor/ folder. Some PHP libraries also need functions that are disabled on shared servers; see PHP disabled functions on shared hosting and top PHP libraries and how to use them.
  • Node.js on shared hosting: the cPanel and DirectAdmin Node.js tool installs your dependencies with its Run NPM Install button. On cPanel, choose Node.js 22 or 24; version 20 has reached end of life. See deploying a Node.js app on shared hosting.
  • Python on shared hosting: the Python application tool creates a virtual environment for your app. See deploying a Python app on shared hosting.
  • App Platform: Node.js apps are detected automatically; other languages deploy with a Dockerfile, where you install dependencies as part of the build. See getting started with the App Platform.
  • VPS: a self-managed VPS gives you root access to install any runtime, package manager or system library you need.
What is the difference between a library and a framework?

You call a library when you need it, and it does one job. A framework provides the structure of the whole application and calls your code at the points it defines. Swapping a library is usually easy; swapping a framework usually means a rewrite.

How do I know if a library is safe to use?

Check that it has recent releases and active maintainers, a licence that suits your project and no open security advisories. Run your package manager's audit command, such as npm audit, pip-audit or composer audit, and keep the lock file in version control.

Why should I commit the lock file?

The lock file records the exact version of every dependency, so every developer and every server installs the same code. Without it, a new install can pull in a newer version that behaves differently or contains a vulnerability.

Should I still use Moment.js or jQuery in new projects?

For new projects, usually not. Moment.js is in maintenance mode and its team recommends alternatives such as date-fns or Luxon. Modern browsers include most of what jQuery was used for. Existing projects can keep them while they plan a move.

Can I run Composer on Domain India shared hosting?

Yes, over jailed SSH (on request). Composer isn't pre-installed, so download composer.phar and run php composer.phar install; if it stops with a proc_open message, run it again with --no-scripts. Or run composer install on your own computer or in CI and upload the project with its vendor folder, or use a VPS or the App Platform.

How do I install npm packages on Domain India shared hosting?

Create the app in the control panel's Node.js tool, upload your code with package.json, and click Run NPM Install. You do not need SSH for this.

Ready to deploy your project? Compare cPanel hosting, the App Platform and a self-managed VPS, or open a support ticket if you are not sure which fits.

Find the right home for your code

Deploy Node.js apps with automatic detection, or any other language with a Dockerfile, on Domain India's App Platform.

See the App Platform

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Programming Libraries: How to Choose and Manage Them