A programming library is a package of ready-made, tested code that you call from your own program, so you don't have to write everything yourself. Almost every modern project depends on dozens of them. This handbook explains what libraries are, how they differ from frameworks, how to choose and manage them safely in 2026, and how to run a project with dependencies on Domain India hosting.
A library is code you call; a framework is code that calls you. Choose libraries that are actively maintained, well documented, compatibly licensed and free of known vulnerabilities. Install them with your language's package manager, commit the lock file, audit dependencies regularly and remove the ones you no longer use. On Domain India shared hosting, Composer isn't pre-installed, so run composer.phar over jailed SSH or build PHP projects locally and upload vendor/; Node.js and Python apps install their dependencies through the control panel's app tools.
1. What a library is
A library gives you functions, classes or components for one job: making HTTP requests, parsing dates, validating input, drawing charts, sending email. You decide when to call it and what to do with the result. Good libraries are:
- Focused: they do one thing well, so you can add or replace them without rewriting your app.
- Reusable: the same code works across many projects.
- Documented: a clear API and examples.
- Maintained: bugs and security issues are fixed in new releases.
2. Library or framework?
| Question | Library | Framework |
|---|---|---|
| Who is in control | Your code calls the library | The framework calls your code |
| Scope | One task | The structure of the whole app |
| Swapping it out | Usually easy | Usually a rewrite |
| Examples | Axios, date-fns, Pandas, Guzzle, Dapper | Laravel, Django, Spring Boot, Angular, Next.js |
Some tools sit in between. React calls itself a library for building user interfaces, but most React apps are built with a framework such as Next.js around it. Vue describes itself as a progressive framework. The label matters less than the question: does this tool decide the shape of my app?
3. Common libraries by language (2026)
Some once-standard libraries now have better options. Moment.js is in maintenance mode, and its own team recommends alternatives such as date-fns or Luxon for new projects. jQuery is rarely needed in new code, because modern browsers have querySelector and fetch built in. Lodash is still fine, but many of its helpers now exist in plain JavaScript.
4. How to choose a library
- Check that it is alive.Look at the date of the latest release, how quickly issues get answers and whether more than one person maintains it.
- Read the documentation first.If you cannot work out how to use it in ten minutes, your team will struggle too.
- Check the licence.MIT, BSD and Apache 2.0 are easy to use in commercial work. GPL and AGPL have conditions you must understand before you ship.
- Check for known vulnerabilities.Search the package in the GitHub Advisory Database or your package manager's audit tool.
- Weigh the size and dependencies.A small helper that pulls in fifty packages adds risk and, in front-end code, download size.
- Confirm it supports your versions.Check the language and runtime versions it requires against the ones your hosting offers.
5. Installing and managing libraries
| Language | Package manager | Lock file | Audit command |
|---|---|---|---|
| JavaScript | npm, pnpm, Yarn or Bun | package-lock.json, pnpm-lock.yaml, yarn.lock, bun.lock | npm audit |
| Python | pip or uv | requirements.txt with pinned versions, uv.lock | pip-audit |
| PHP | Composer | composer.lock | composer audit |
| Java | Maven or Gradle | Gradle lock files | OWASP Dependency-Check |
| C# and .NET | NuGet | packages.lock.json | dotnet list package --vulnerable |
Good habits for every language:
- Commit the lock file. It records the exact version of every package, so every install and every server gets the same code.
- Understand version ranges. Most ecosystems use semantic versioning:
^2.3.0accepts any 2.x release from 2.3.0, but not 3.0. A major version change can break your code, so upgrade it on purpose and test. - Keep production installs lean. Install only runtime dependencies on the server, for example
npm ci --omit=devorcomposer install --no-dev. - Use a virtual environment for Python, so each project has its own packages.
- Remove what you don't use. Every dependency is code you are trusting.
For hands-on guides, see JavaScript package managers: npm, Yarn, pnpm and Bun and installing Composer and managing PHP libraries.
6. Security and the software supply chain
Libraries are a common way in for attackers, because one popular package runs inside thousands of apps.
- Log4Shell (2021) was a flaw in the Java logging library Log4j 2 that let attackers run code on servers simply by getting a crafted string logged. Many teams did not know they used Log4j until they searched for it.
- The xz Utils backdoor (2024) was slipped into a compression library by a contributor who had gained the maintainers' trust over years, and was caught shortly before it reached stable Linux releases.
- Typosquatting packages with names one letter away from popular ones, and hijacked maintainer accounts, regularly push malicious versions to npm and PyPI.
Pin versions with a lock file, run your package manager's audit command in CI, turn on automated update alerts such as Dependabot or Renovate, and check the exact package name before you install. Update vulnerable packages promptly rather than waiting for the next big release.
7. When libraries cause problems
- Version conflicts: two packages need different versions of the same dependency. Read the package manager's error, upgrade the older package, or look for a maintained alternative.
- Bloat: a large library used for one function slows builds and pages. Import only what you need, or use the built-in language feature.
- Abandoned packages: if a library stops getting updates, plan a replacement before a vulnerability forces one.
- Debugging inside a library: reproduce the problem in a small script, read the library's changelog and issue tracker, and check whether your version is current before reporting a bug.
8. Running projects with libraries on Domain India
- PHP on shared hosting: Composer isn't pre-installed, but over jailed SSH you can run
php composer.phar install --no-dev; if it stops with a proc_open message, run it again with--no-scripts. Or runcomposer install --no-devon your own computer or in CI and upload the project with itsvendor/folder. Some PHP libraries also need functions that are disabled on shared servers; see PHP disabled functions on shared hosting and top PHP libraries and how to use them. - Node.js on shared hosting: the cPanel and DirectAdmin Node.js tool installs your dependencies with its Run NPM Install button. On cPanel, choose Node.js 22 or 24; version 20 has reached end of life. See deploying a Node.js app on shared hosting.
- Python on shared hosting: the Python application tool creates a virtual environment for your app. See deploying a Python app on shared hosting.
- App Platform: Node.js apps are detected automatically; other languages deploy with a Dockerfile, where you install dependencies as part of the build. See getting started with the App Platform.
- VPS: a self-managed VPS gives you root access to install any runtime, package manager or system library you need.
What is the difference between a library and a framework?
You call a library when you need it, and it does one job. A framework provides the structure of the whole application and calls your code at the points it defines. Swapping a library is usually easy; swapping a framework usually means a rewrite.
How do I know if a library is safe to use?
Check that it has recent releases and active maintainers, a licence that suits your project and no open security advisories. Run your package manager's audit command, such as npm audit, pip-audit or composer audit, and keep the lock file in version control.
Why should I commit the lock file?
The lock file records the exact version of every dependency, so every developer and every server installs the same code. Without it, a new install can pull in a newer version that behaves differently or contains a vulnerability.
Should I still use Moment.js or jQuery in new projects?
For new projects, usually not. Moment.js is in maintenance mode and its team recommends alternatives such as date-fns or Luxon. Modern browsers include most of what jQuery was used for. Existing projects can keep them while they plan a move.
Can I run Composer on Domain India shared hosting?
Yes, over jailed SSH (on request). Composer isn't pre-installed, so download composer.phar and run php composer.phar install; if it stops with a proc_open message, run it again with --no-scripts. Or run composer install on your own computer or in CI and upload the project with its vendor folder, or use a VPS or the App Platform.
How do I install npm packages on Domain India shared hosting?
Create the app in the control panel's Node.js tool, upload your code with package.json, and click Run NPM Install. You do not need SSH for this.
Ready to deploy your project? Compare cPanel hosting, the App Platform and a self-managed VPS, or open a support ticket if you are not sure which fits.
Deploy Node.js apps with automatic detection, or any other language with a Dockerfile, on Domain India's App Platform.
See the App Platform