Server requirements
Use a currently supported, patched PHP branch (PHP 8.3 or later recommended), MySQL/MariaDB with InnoDB and utf8mb4, and Apache with mod_rewrite and AllowOverride enabled. The code’s minimum PHP syntax level is 8.1; that is not a recommendation to deploy an unsupported branch. Enable PDO MySQL, mbstring, fileinfo, OpenSSL, cURL and GD.
Upgrade from 2.3.6
- Back up the database, application files,
app/config.phpandstorage/. Verify the backup can be restored. Use a staging copy first. - Temporarily pause write traffic while replacing files. Upload this package over the application, preserving the existing
app/config.phpand every existing storage file. Do not run the installer. - A fully upgraded 2.3.6 database needs no schema migration for 2.4. Do not import
database/schema.sqlinto the live database as an upgrade. - Remove superseded root
UPDATE-v*.md/UPDATE-v*.txtnotes and old documentation files listed inRELEASE-CLEANUP.txt. ZIP extraction does not delete files left from older releases. Never delete live storage or configuration. - Remove
install/and previously applied rootupgrade-v*.phpscripts from the deployed server after validation. Historical migration scripts are included for recovery/reference; do not rerun them without a specific migration need. - Open
/manualand each role guide, verify sign-in and two-factor sign-in, then test a representative submission and editorial workflow before reopening traffic.
Fresh installation
- Create an empty database and a dedicated database user. Upload application files, including
.htaccess, to the intended document root or subdirectory. - Make
app/andstorage/writable by the hosting PHP process. Avoid world-writable permissions. Optionally copy.user.ini.exampleto.user.iniafter reviewing host limits. - Restrict access to the installer at the hosting layer while setting up. Open
/install/, supply database credentials and the canonical HTTPS URL, and create the Platform Administrator. - The installer creates schema, configuration and an installation lock. It refuses installation when an existing configuration or lock is present. Remove the installer after success.
- Create the publisher and journal, configure email and policies, assign accounts, and verify delivery and role permissions.
Daily scheduled task
In cPanel Cron Jobs, run the hosting account’s PHP binary against the absolute path to cron/reminders.php, for example:
0 3 * * * /usr/local/bin/php -q /home/CPANELUSER/public_html/cron/reminders.php
Replace the account, path and PHP binary with your actual values. Review publisher retention first: this command sends reminders and deletes eligible expired drafts. Retain cron output in a private log for troubleshooting.
Rollback
Restore the pre-upgrade application files and configuration. Version 2.4 adds no schema changes; restore the database and storage together only if the rollback requires reverting data written after deployment.
Hosting verification
Confirm direct requests to /app/, /database/, /storage/ and /docs/ are denied. Public manuals are served through /manual and /manual-asset/. Configure equivalent denials before using non-Apache hosting.