Server requirements
What the server has to provide. The installer checks every item on this page and tells you which ones fail.
CertiFlow is written for ordinary shared hosting with a control panel. It needs no shell access, no Node.js, no Docker, and no Composer: the dependencies ship already installed inside the package.
Hosting
| Item | Requirement |
|---|---|
| Web server | Apache with mod_rewrite, or Nginx. The package includes the Apache rules; the Nginx equivalent is in installation. |
| Database | MySQL 5.7 or newer, or MariaDB 10.3 or newer. The schema uses JSON columns, so older versions will not accept it. |
| HTTPS | Required in practice. Sign-in cookies are marked HTTPS-only as soon as you enable it, and certificate links you publish should not be plain HTTP. |
| Disk space | About 60 MB for the application, plus your own growth: one issued PDF is typically 100 KB to 2 MB, and background images are stored once per template. |
| An SMTP mailbox you control. Sending through your own domain is what keeps delivered certificates out of spam folders. | |
| Scheduled jobs | The ability to run a PHP file on a schedule, called Cron Jobs in most control panels. |
PHP
PHP
PHP 8.1.0 or newer. PHP 8.2 and 8.3 are also supported.
Required PHP extensions
The installer stops if any of these is missing.
| Extension | What it is used for |
|---|---|
pdo_mysql | The database driver. Enable it in the hosting control panel, under PHP extensions. |
mbstring | Multibyte string handling, used by every piece of text in the interface. |
openssl | Encryption of stored SMTP credentials and two-factor secrets. |
json | Configuration, audit metadata and certificate layouts are stored as JSON. |
ctype | Character checks used by validation. |
fileinfo | Detects the true type of an uploaded file, which the upload checks rely on. |
zip | Reading .xlsx import files and writing exports. |
curl | Secure outbound delivery of signed webhook events. |
Optional PHP extensions
The installer reports these as advice. The product runs without them.
| Extension | What it adds |
|---|---|
gd | Faster image handling for logo and certificate background uploads. |
intl | Locale-aware sorting and formatting. |
Writable directories
The web server user must be able to write to each of these. The installer checks them all.
storage/storage/cache/storage/certificates/storage/exports/storage/logs/storage/private/storage/qr/storage/translations/
PHP settings
The package ships a .user.ini that sets these on most shared hosting. If your
host ignores it, set them in the control panel instead.
| Setting | Value | Why |
|---|---|---|
upload_max_filesize | 10M or more | Import files and certificate background images. Keep it at or above UPLOAD_MAX_MB. |
post_max_size | 12M or more | Must exceed upload_max_filesize, or a large upload is silently discarded. Keep it at or above REQUEST_MAX_MB. |
memory_limit | 128M or more | Rendering a PDF and reading an .xlsx both hold the file in memory. |
max_execution_time | 60 or more | Confirming a large import in one request. |
display_errors | Off | An error page must never show a visitor your file paths. |
Checking before you buy hosting. Most providers publish their PHP version
and extension list. The two that are most often missing on cheap plans are
zip and fileinfo. Without zip the product cannot read
.xlsx imports or write exports.
Checking after installation
Sign in as an Admin and open /admin/diagnostics. It runs the same checks as
the installer and adds the PHP version, the web server, the database version, the active
language and the timezone. That page is the right thing to send with a support request.