Composer is the de facto dependency manager for PHP. It lets you install and manage libraries like PHPMailer, Guzzle, Carbon, and Stripe SDK with a single command. On DirectAdmin Shared Hosting with SSH access, you can run Composer directly in the terminal — or install packages locally and upload the vendor/ folder via FTP if SSH isn't available.
Verify PHP CLI and SSH Access
Composer requires PHP CLI (Command Line). Check it via SSH:
ssh [email protected]
php -v
# PHP 8.3.x (cli)
If the default PHP version isn't what you need, use the versioned binary that DirectAdmin provides:
php83 -v
Install Composer on Hosting
cd ~
curl -sS https://getcomposer.org/installer | php
# Creates composer.phar in the current directory
Add an alias so you can type composer instead of php composer.phar:
echo 'alias composer="php ~/composer.phar"' >> ~/.bashrc
source ~/.bashrc
composer --version
Create a PHP Project with Composer
composer.json (basic structure)
{
"require": {
"phpmailer/phpmailer": "^6.9",
"guzzlehttp/guzzle": "^7.8",
"nesbot/carbon": "^3.0"
}
}
Install Packages
cd ~/domains/yourdomain.com/public_html
composer install
Composer creates a vendor/ directory containing all packages and the vendor/autoload.php file.
Understanding the Files Composer Creates
After a successful composer install, your project directory will contain several important files and folders:
| File / Folder | Purpose | Commit to Git? |
|---|---|---|
composer.json |
Declares dependencies and project configuration | Yes |
composer.lock |
Locks exact versions so every team member gets the same packages | Yes |
vendor/ |
All installed package code and the autoloader | No — add to .gitignore |
vendor/autoload.php |
The file you require in your code to enable all packages | No — auto-generated |
The composer.lock file is critical for teams and production deployments. It guarantees every composer install installs the exact same package versions, preventing the "works on my machine" problem caused by version drift between developers and the server.
Managing Dependencies Like a Pro
Choosing the Right Version Constraint
How you write version constraints in composer.json significantly affects your project's stability and security update coverage:
| Constraint | Meaning | Best for |
|---|---|---|
^6.9 |
≥6.9.0 and <7.0.0 (accepts minor updates) | Most production projects |
~6.9 |
≥6.9.0 and <6.10.0 (patch updates only) | High-risk integrations |
6.9.* |
Any 6.9.x patch version | Locking at minor version |
6.9.1 |
Exact version only | Avoid — misses security patches |
Autoloading Your Own Project Classes
Beyond loading package classes, Composer can also autoload your own application classes using PSR-4 namespacing:
{
"require": {
"phpmailer/phpmailer": "^6.9"
},
"autoload": {
"psr-4": {
"App\\": "src/"
}
}
}
After adding the autoload section, run composer dump-autoload to regenerate the autoloader. Any class in the src/ directory under the App\ namespace will then be loaded automatically.
Use Packages in PHP Code
format('d/m/Y H:i');
// PHPMailer example
$mail = new PHPMailer(true);
$mail->isSMTP();
$mail->Host = 'smtp.yourdomain.com';
// ... send email
Popular Packages and Real-World Usage Examples
Stripe PHP SDK — Accept Online Payments
The Stripe SDK enables your PHP project to accept credit card payments, PromptPay, and QR Code payments with minimal code.
composer require stripe/stripe-php
require_once __DIR__ . '/vendor/autoload.php';
\Stripe\Stripe::setApiKey('sk_live_xxx');
$intent = \Stripe\PaymentIntent::create([
'amount' => 50000, // amount in smallest currency unit (satang for THB)
'currency' => 'thb',
]);
echo $intent->client_secret;
Guzzle HTTP Client — Make API Requests
Guzzle is the go-to HTTP client for PHP, offering async requests, middleware support, and automatic retries out of the box.
composer require guzzlehttp/guzzle
use GuzzleHttp\Client;
$client = new Client(['base_uri' => 'https://api.example.com']);
$response = $client->get('/users', [
'headers' => ['Authorization' => 'Bearer token123'],
'timeout' => 5,
]);
$data = json_decode($response->getBody(), true);
Carbon — Work with Dates and Times
Carbon extends PHP's native DateTime class with a fluent API for formatting, timezone conversion, localization, and human-readable diffs.
composer require nesbot/carbon
use Carbon\Carbon;
Carbon::setLocale('en');
$now = Carbon::now('Asia/Bangkok');
echo $now->format('d/m/Y H:i'); // 07/06/2026 15:30
echo $now->diffForHumans(); // just now
echo $now->addDays(7)->toDateString(); // 2026-06-14
Intervention Image — Resize and Convert Images
Intervention Image handles resizing, cropping, watermarking, and format conversion (WebP, JPG, PNG) directly from PHP — no shell commands needed.
composer require intervention/image
use Intervention\Image\ImageManager;
use Intervention\Image\Drivers\Gd\Driver;
$manager = new ImageManager(new Driver());
$image = $manager->read('upload.jpg');
$image->resize(width: 820, height: 340);
$image->save('output.webp'); // automatically converts to WebP
No SSH? Upload vendor/ via FTP
If SSH isn't available on your plan, install Composer locally then upload the vendor/ folder via FTP:
- Install Composer locally (Mac:
brew install composer/ Windows: download installer) - Run
composer installin your project folder - Upload the
vendor/directory andcomposer.lockto Hosting via FileZilla or FTP
Important: Never commit the vendor/ directory to Git — add /vendor to .gitignore instead. Use composer install on the server or in your CI/CD pipeline to recreate it.
Common Composer Commands
# Install all dependencies from composer.json
composer install
# Add a new package
composer require stripe/stripe-php
# Update all packages to latest allowed versions
composer update
# Update a specific package
composer update phpmailer/phpmailer
# Remove a package
composer remove guzzlehttp/guzzle
# List installed packages
composer show
Security Best Practices for Composer in Production
Running Composer on a live hosting environment requires extra attention to security. Follow these practices to keep your project protected:
- Block web access to vendor/ — Create a
vendor/.htaccessfile containingDeny from all. This prevents anyone from directly accessing your installed package source code via a browser. - Run composer audit regularly — This command checks your installed packages against a database of known security vulnerabilities (CVEs) and warns you if any package needs updating.
- Skip dev dependencies in production — Run
composer install --no-dev --optimize-autoloaderto avoid installing testing and debugging tools on your live server. - Validate your composer.json — Run
composer validatebefore deploying to catch JSON syntax errors or invalid constraint formats that might cause install failures.
# Audit installed packages for known vulnerabilities
composer audit
# Install production-only dependencies with optimized autoloader
composer install --no-dev --optimize-autoloader
# Validate your composer.json before deployment
composer validate
Production Tip: The --optimize-autoloader flag generates a static class-map instead of scanning PSR-4 directories on every request. This speeds up autoloading by 20–30%, which matters most on shared hosting where memory is limited and OPCache may not be available.
Common Issues on Shared Hosting
Memory limit exceeded
php -d memory_limit=512M composer.phar install
Need a specific PHP version
php83 ~/composer.phar install
SSH session times out
Use nohup to keep Composer running after SSH disconnects:
nohup php ~/composer.phar install > composer.log 2>&1 &
Need Hosting with SSH Access and PHP 8.3?
All AsiaGB Hosting plans support PHP 8.3, SSH access, and Composer. Starting at ฿500/year.
View Hosting Plans