Composer on shared hosting: installing it and running it

Composer is not installed as a command on the server, but you do not need it that way. You download a single file, composer.phar, into your account and run it with PHP: php composer.phar install. You need a command line, which means the cPanel Terminal or SSH, depending on whether your account has a shell.

Installing composer.phar

1 Open the cPanel Terminal (or connect over SSH, on port 2299) and go into the project folder, for example cd ~/my-project.
2 Check which PHP the php command uses: type php -v. If it is not the project’s version, use the full path of the right one in the commands below, which looks like /opt/alt/php82/usr/bin/php (swap 82 for the version you want, without the dot).
3 Download the installer: php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');". The Composer download page also publishes the installer’s checksum; it is worth checking it before running the file.
4 Run it: php composer-setup.php. The file composer.phar appears.
5 Delete the installer: php -r "unlink('composer-setup.php');".
6 Install the project’s dependencies: php composer.phar install. In production, php composer.phar install --no-dev --optimize-autoloader leaves out what is only for development.

install or update?

Command What it does
composer install Installs exactly what the composer.lock file says. This is the one to run on the server, so it matches what you tested.
composer update Looks for newer versions and rewrites composer.lock. Run it on your own computer, test, then take the result to the server.
composer require package Adds a package to the project and installs it.
“Killed”, or the command stops halfway. The account has memory and process limits (see the limits nobody advertises), and Composer uses a lot while it resolves dependencies. Try php -d memory_limit=-1 composer.phar install. If it still gets killed, run install on your computer and send the vendor folder over SFTP.
Do not leave composer.phar or the vendor folder where site visitors can reach them when the project allows it: keep the application outside the public folder and leave only the entry file inside. And never publish the .env file. See keeping passwords out of your code.
No shell on your account? Not every account has a terminal. Run composer install on your own computer, with the same PHP version, and send vendor and composer.lock over SFTP. The result is the same.

The libraries Composer installs and your application’s code are yours, and we do not maintain them. The boundary is written in how far our support goes. For Laravel, which uses Composer from end to end, see getting a Laravel application running.

Not sure your account has a Terminal? Ask us, with your domain name.

Open a support ticket

SEE ALSO

The cPanel Terminal: a command line with nothing to install

Getting a Laravel application running

Viewing and adjusting your PHP configuration

SFTP instead of FTP

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $5.36/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?