# Deployment to remote shared web host?

**URL:** <https://discourse.slimframework.com/t/deployment-to-remote-shared-web-host/5565>\
**Category:** Questions\
**Created:** [March 17, 2023, 5:40pm UTC](https://discourse.slimframework.com/t/deployment-to-remote-shared-web-host/5565 "2023-03-17T17:40:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![robm99x](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@robm99x](https://discourse.slimframework.com/u/robm99x)\
**Post date:** [March 17, 2023, 5:40pm UTC](https://discourse.slimframework.com/t/deployment-to-remote-shared-web-host/5565/1 "2023-03-17T17:40:38Z")

</div>

I think I talked about this before, but don’t remember. I’ve read the Slim 3/4 docs on deployment to remote web server. I typically use ‘rsync’ command with a “–exclude-from” of files not to copy like this:

`rsync -rav --exclude-from 'publish-exclude-list.txt' ./ user@remote:~/{subdir}/`

This copies all my files and all the “vendor” files from the Slim skeleton. Not to long back, my website got hacked because the `vendor/phpunit` has the ability for hackers to do some not-so-great ™ things.

So I updated my exclude list to be like this

```auto
publish.sh
publish-exclude-list.txt
*.code-workspace
.[A-Za-z]*
composer.phar
logs
vendor/phpunit

```

Does anyone have recommendations of other Slim Skeleton files not to deploy beside `phpunit`?

TIA!

---

<div class="post-metadata">

**Author:** ![odan](https://avatars.discourse-cdn.com/v4/letter/o/9de053/32.png) [@odan](https://discourse.slimframework.com/u/odan)\
**Post date:** [March 19, 2023, 9:53am UTC](https://discourse.slimframework.com/t/deployment-to-remote-shared-web-host/5565/2 "2023-03-19T09:53:30Z")

</div>

It’s always a good practice to exclude any unnecessary files or directories when deploying a web application, to minimize the risk of security vulnerabilities and reduce the deployment time.

To start with, I would recommend creating a **build script** that generates a deployment “artifact”.

This script would call for example the `composer install --no-dev --optimize-autoloader` command to install only the needed dependencies and to optimize the composer autoloader for performance.

---

<div class="post-metadata">

**Author:** ![robm99x](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@robm99x](https://discourse.slimframework.com/u/robm99x)\
**Post date:** [March 20, 2023, 8:26pm UTC](https://discourse.slimframework.com/t/deployment-to-remote-shared-web-host/5565/3 "2023-03-20T20:26:26Z")

</div>

@odan the problem is, aside from

```auto
	"require-dev" : {
		"phpunit/phpunit" : ">=4.8"
	},

```

I don’t know what else I should NOT deploy. I’m looking for ideas specifically from others or the author of the Slim Skeleton app.
