You can deploy Yii on almost any PHP host, from a $3 shared plan to a Kubernetes cluster, because it is ordinary PHP with Composer dependencies and no compiled extension. The one requirement that decides everything is the document root: Yii keeps its entry script in a subdirectory (web in Yii2, public in Yii3) and the rest of the application must sit outside anything the web server can reach. If your host lets you point a domain at a subfolder, you are done. If it does not, you have some work ahead.
web for Yii2 or public for Yii3, deploy with composer install --no-dev --optimize-autoloader, and set YII_DEBUG to false in production. Yii2 is in security fix only mode and reaches end of life in late 2027.Below: where Yii2 and Yii3 actually stand right now, seven hosting options compared, the Apache and Nginx configuration for the subdirectory problem, and a Composer based deployment that does not break on a slow shared box.
Yii2 or Yii3: check this before choosing a host
Yii3 was released at the end of 2025 and is the version to start new projects on. The official release cycle page lists Yii3 as requiring PHP 8.2 or newer, with active support running to the end of 2030 and security fixes to the end of 2032.
Yii2 is a different story. The 2.0.50 and later branch is feature frozen, accepts PHP 7.3 through 8.4, and is in security fix only mode until late November 2026, with end of life in November 2027. The older 2.0.49 and earlier branch reaches end of life at the same November 2026 date. If you are hosting a Yii2 application today, that timeline should shape your hosting choice, because you will need a PHP version your host still offers when you eventually migrate.
| Version | PHP required | Public directory | Support status |
|---|---|---|---|
| Yii 3 | 8.2 or newer | public | Active, security fixes into the 2030s |
| Yii 2.0.50 and later | 7.3 through 8.4 | web | Feature frozen, security fixes only |
| Yii 2.0.49 and earlier | 5.4 through 8.3 | web | Reaching end of life |
| Yii 1.1 | Legacy | Varies | Long past end of life, migrate |
Seven places to deploy Yii, compared
The differences that matter are document root control, whether you get SSH for Composer, and whether you can run console commands and cron for queues and migrations.
| Option | Root control | SSH and Composer | Typical cost | Best for |
|---|---|---|---|---|
| Shared cPanel hosting | Usually yes, per addon domain | On mid tier plans | Low single digits per month | Small sites, client work |
| Budget shared without SSH | Sometimes | No, upload vendor manually | A few dollars per month | Static content, avoid if possible |
| DigitalOcean Droplet | Full | Yes | $6 per month for 1 GB | Most production apps |
| Vultr or Linode | Full | Yes | $5 per month for 1 GB | Cheapest route to root access |
| Cloudways managed cloud | Full, through the panel | Yes | From about $11 per month | Teams who want staging and backups |
| Docker on any provider | Defined in the image | Yes | Cost of the instance | Reproducible builds and CI |
| PaaS such as Render or Platform.sh | Set in a config file | Yes, during build | From about $7 per month | Push to deploy workflows |
For most teams the honest recommendation is a small VPS. It costs the same as a mid tier shared plan, removes every document root argument, and gives you cron for the queue runner. The reasoning is identical to what we lay out in the guides to deploying Laravel on Vultr and running CakePHP on cloud hosting.
Installing Yii and setting the document root
Start with the official application template. Yii2 and Yii3 differ in package name and public directory, so pick the right one.
# Yii 2 basic template
composer create-project --prefer-dist yiisoft/yii2-app-basic basic
# Yii 3 application template
composer create-project yiisoft/app myprojectOn a VPS with Nginx, point root at the public directory and route everything else through the entry script.
server {
listen 80;
server_name app.example.com;
root /var/www/basic/web;
index index.php;
location / {
try_files $uri $uri/ /index.php?$args;
}
location ~ ^/assets/.*\.php$ { deny all; }
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.3-fpm.sock;
try_files $uri =404;
}
location ~* /\. { deny all; }
}On Apache with cPanel, the clean approach is to set the addon domain or subdomain document root to /home/user/basic/web in the panel. That keeps the application code above the web root where it belongs.
When you cannot change the document root
Some budget hosts nail every domain to public_html and will not move it. You have two workable options and one bad one.
The first option is a symlink, if the host allows them. Deploy the project to your home directory and link the public folder into place.
cd ~
composer create-project --prefer-dist yiisoft/yii2-app-basic basic
rm -rf ~/public_html
ln -s ~/basic/web ~/public_htmlThe second option is an .htaccess rewrite in public_html that forwards every request into the web folder while keeping the application code in a sibling directory.
RewriteEngine On
RewriteCond %{REQUEST_URI} !^/web/
RewriteRule ^(.*)$ /web/$1 [L]
# and inside web/.htaccess
RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . index.phpweb into public_html and leaving config, runtime and vendor beside it. That exposes your database credentials to anyone who guesses the path. If a host forces that layout, change hosts.Deploying and hardening for production
Deploy with Composer, never by uploading a zip of your development folder. Install without development dependencies and with an optimized autoloader, then run migrations and clear caches.
cd /var/www/basic
git pull origin main
composer install --no-dev --optimize-autoloader --no-interaction
php yii migrate --interactive=0
php yii cache/flush-all
sudo systemctl reload php8.3-fpmTurn debug mode off. In Yii2 the entry script sets YII_DEBUG and YII_ENV, and leaving them at development values in production exposes stack traces and the debug toolbar to the public. Also make runtime and web/assets writable by the web server user, and nothing else.
sudo chown -R www-data:www-data /var/www/basic/runtime /var/www/basic/web/assets
sudo chmod -R 755 /var/www/basic
sudo find /var/www/basic/config -type f -exec chmod 640 {} \;Add a cron entry for the queue worker if your application uses one, and a Let’s Encrypt certificate with certbot --nginx. If you are weighing Yii against a compiled framework for raw throughput, the trade offs are covered in our guide to where to host Phalcon, and for another small framework comparison see deploying FuelPHP on hosting.
Troubleshooting a Yii deployment
Every URL except the home page returns 404. Rewriting is off or the pretty URL rules are not matching. Confirm mod_rewrite on Apache or the try_files line on Nginx, and check that urlManager has showScriptName set to false.
The site shows a blank page with no error. Debug mode is off and something fatal happened. Read runtime/logs/app.log and the PHP error log rather than guessing. A missing extension or an unwritable runtime directory covers most cases.
Assets do not load after deployment. The web/assets directory is not writable, so Yii cannot publish bundles. Fix ownership, then delete the stale contents of the directory and let it regenerate.
Composer fails on a shared host. Memory limit. Run php -d memory_limit=-1 composer.phar install, or build the vendor directory locally and upload it, which is the standard workaround where you have no shell.
Migrations work locally and fail on the server. Different PHP or database versions. Check php -v and the database server version on both sides, and remember that Yii2 caps out at PHP 8.4 on the supported branch.
Frequently asked questions
Can I run Yii on shared hosting?
Yes, provided you can point the domain at the framework’s public subdirectory and preferably reach a shell for Composer. Yii has no compiled extension requirement, so any shared plan with a supported PHP version and rewriting enabled will run it.
Should I start a new project on Yii2 or Yii3?
Yii3 for anything new. It was released at the end of 2025, requires PHP 8.2 or newer, and has support committed well into the next decade. Yii2 is feature frozen and moves to end of life in late 2027.
Why does Yii keep the entry script in a subdirectory?
Security. Only the contents of web or public should be reachable over HTTP. Configuration files, logs, migrations and the vendor tree live outside it, so a misconfigured server cannot serve them as plain text.
What PHP version does Yii need?
Yii3 needs PHP 8.2 or newer. The supported Yii2 branch accepts PHP 7.3 through 8.4. Target 8.2 or above either way, since older releases no longer receive upstream security fixes and most hosts have retired them.
Do I need a VPS for Yii?
Not strictly, but it removes the most common friction. A $5 to $6 instance gives you document root control, SSH for Composer, and cron for migrations and queue workers, all of which shared hosting restricts to some degree.
The bottom line
Yii deploys anywhere PHP runs, so the hosting decision comes down to three practical questions: can you point the document root at the public subdirectory, can you run Composer on the server, and can you schedule console commands. Shared hosting answers yes to the first and maybe to the others. A VPS answers yes to all three for about the same money.
Pair that with the version question. Start new work on Yii3 and plan a migration path for anything still on Yii2, because the security window closes sooner than most teams expect. Choose a host that will still offer the PHP version you need when that migration lands.
About this article: GeekBlog covers U.S. technology news, AI, phones, smartwatches and gaming. Every story is written and checked under our Editorial Policy. Spotted a mistake or have a story tip? Contact our editors.

