Besides psr-4, autoload takes classmap (scan directories of non-PSR code) and files (always required: the only way to ship functions). scripts names commands, and config.platform makes Composer 5,243 resolve for your production PHP rather than the local one. The package gained these keys:
{
"autoload": {
"psr-4": { "Acme\\ShopMoney\\": "src/" },
"files": ["src/functions.php"]
},
"autoload-dev": { "psr-4": { "Acme\\ShopMoney\\Tests\\": "tests/" } },
"scripts": {
"test": "phpunit --colors=never tests",
"check": ["@composer validate --strict", "@test"]
},
"config": { "platform": { "php": "8.4.1" } }
}The platform is part of the lock's content-hash, so validate --strict reported "The lock file is not up to date" until composer update --lock; then composer check ran PHPUnit 13.3.4 79,198 ("OK (2 tests, 3 assertions)"). composer require php:^8.6 failed with "your php version (8.4.1; overridden via config.platform, actual: 8.5.4) does not satisfy that requirement", and the generated vendor/composer/platform_check.php stops a server with too old a PHP at runtime.
The default autoloader applies the PSR-4 rules and checks the disk. dump-autoload -o builds a classmap first; --classmap-authoritative also trusts it completely, so a class missing from it costs no disk check. bench.php created 2,000 one-line classes, then called class_exists() on 20,000 names that do not exist:
for mode in "" -o --classmap-authoritative; do
composer dump-autoload $mode 2>&1 | tail -1
php bench.php
doneGenerated autoload files load 2,000: 36.5 ms 20,000 misses: 92.2 ms Generated optimized autoload files containing 2001 classes load 2,000: 33.0 ms 20,000 misses: 87.5 ms Generated optimized autoload files (authoritative) containing 2001 classes load 2,000: 40.4 ms 20,000 misses: 5.9 ms
Loading times wander by several milliseconds between runs, since compiling dominates with OPcache off, but authoritative mode made misses fifteen to twenty times cheaper in every run. Classes added without re-dumping become invisible, so keep it for deploy builds.