STOCKFISH.IO — CPANEL DEPLOYMENT GUIDE ==================================== This package is plain static HTML/CSS/JavaScript. No Node, npm, PHP, database, server-side analysis, or build step is required on Namecheap. Engine binaries are intentionally NOT included. The chess board works without them. 1. BACK UP FIRST In cPanel File Manager, open Settings and enable Show Hidden Files (dotfiles). Back up the existing public_html contents INCLUDING .htaccess, assets and engine. Store the backup outside public_html (for example in your hosting home directory), then download it to your computer. Do not leave a publicly downloadable backup ZIP. 2. UPLOAD THE REPLACEMENT SITE Upload stockfish-io-deploy.zip into /public_html. Extract it into /public_html. The ZIP contains index.html at its root, NOT a stockfish-io subfolder. Confirm overwrite/replace for matching files. If cPanel refuses to overwrite during extraction, extract into a temporary folder outside public_html, then copy the extracted contents into public_html with overwrite. Replace index.html, source.html, robots.txt, sitemap.xml, INSTALL.txt, .htaccess, assets/css/style.css and assets/js/app.js. Add assets/js/engine.js, assets/vendor/, and the engine license/source notes. Merge directories; do not delete public_html. Leave .well-known, cgi-bin, nc_assets and hosting-managed files/directories alone. The supplied .htaccess is based on the attached project. If the live .htaccess has additional host-managed rules added since then, preserve them when merging it. Do not preserve an old CSP header that duplicates or conflicts with the new one. Delete the uploaded deployment ZIP after extraction. After backup, remove the old stockfish-io-mvp.zip visible in your screenshot from public_html too. Old unrelated pages may be retained if needed; they are not used by this app. 3. INSTALL THE OPTIONAL STOCKFISH ENGINE Open this exact browser-build release (not a Windows/macOS/Linux executable): https://github.com/nmrugg/stockfish.js/releases/tag/v19.0.0 Expand Assets. Download exactly these TWO matching files, without renaming: stockfish-19-lite-single.js https://github.com/nmrugg/stockfish.js/releases/download/v19.0.0/stockfish-19-lite-single.js stockfish-19-lite-single.wasm https://github.com/nmrugg/stockfish.js/releases/download/v19.0.0/stockfish-19-lite-single.wasm Upload BOTH directly into /public_html/engine/ using cPanel File Manager. Do not put them inside another engine or release folder. Do not choose lite.js, single.js, the multithreaded build, or a .wasm from a different release. No separate neural-network download is needed for this verified lite-single pair. The JS file is 21,415 bytes; the WASM file is 1,787,571 bytes for the tested release. Also download the matching source archive: https://github.com/nmrugg/stockfish.js/archive/refs/tags/v19.0.0.tar.gz Rename that archive to stockfishjs-19-source.tar.gz and upload it, UNEXTRACTED, to /public_html/engine/. Keep COPYING.txt and SOURCE.txt there. The source page links to this archive and the exact upstream source/build instructions. 4. EXPECTED DIRECTORY CONTENTS public_html/ .htaccess index.html source.html robots.txt sitemap.xml INSTALL.txt assets/ css/style.css js/app.js js/engine.js vendor/chess.js vendor/chess-LICENSE.txt engine/ COPYING.txt SOURCE.txt stockfish-19-lite-single.js <-- you add this stockfish-19-lite-single.wasm <-- you add this stockfishjs-19-source.tar.gz <-- you add this .well-known/ <-- preserve existing host directory [other existing hosting files] File permissions normally 0644; directories 0755. Never use 0777. 5. VERIFY THE DEPLOYMENT Open https://stockfish.io/ and hard refresh (Mac: Command+Shift+R). The board must be square. Resize the browser, select e2 then e4, Flip, and Reset. Before engine installation: Engine files missing, Analyze disabled, board usable. After engine installation: Loading engine, Analyzing, then Engine ready. Evaluation, depth, nodes and best line should populate. Searches stop at depth 17 or about 8 seconds; slower devices may take longer to load the engine initially. Make several moves quickly and press Analyze again. Results must match the newest position. Scores are from White's perspective: positive favors White; -M3 means Black has a forced mate in three. Flip does not change the game or score perspective. Checkmate/stalemate/draw messages appear beside the board. Reset retains orientation. Open these URLs directly: https://stockfish.io/engine/stockfish-19-lite-single.js https://stockfish.io/engine/stockfish-19-lite-single.wasm https://stockfish.io/engine/stockfishjs-19-source.tar.gz https://stockfish.io/source.html https://stockfish.io/assets/vendor/chess-LICENSE.txt http://stockfish.io/ (should redirect to HTTPS) The JS URL should show/download JavaScript, not an HTML error page. The WASM URL should download a binary, not display your site's home page. In Developer Tools > Network, reload and filter for stockfish. Both HEAD checks and actual loads should succeed (200, or valid cached response). The WASM response Content-Type must be application/wasm; JS must have a JavaScript MIME type. 6. IF THE ENGINE DOES NOT START - 404: check exact spelling, lowercase, folder nesting, and that BOTH files uploaded. - 403: check file permissions, host restrictions and ModSecurity logs; do not disable protections broadly. Ask hosting support about the specific blocked URL. - 500 after replacing .htaccess: restore the backed-up .htaccess, inspect cPanel Errors, and ask hosting support which directive failed before changing it. - MIME/nosniff error: confirm AddType directives and that no redirect/error page is being returned for a .js or .wasm request. - CSP refusal: inspect the response CSP. script-src must permit 'self' and 'wasm-unsafe-eval'; worker-src and connect-src must permit 'self'. Check for duplicate CSP headers from a proxy/host. Do not add unrestricted unsafe-eval. - CompileError / WebAssembly / aborted runtime: re-upload the matching release pair, clear the browser/site cache, and try an up-to-date browser. - Timeout: check network access, then reload. The page reports failure and keeps the board usable. Initialization allows 45 seconds after file availability checks. - SharedArrayBuffer / cross-origin isolation errors: you uploaded the wrong build. This single-thread build needs neither COOP/COEP nor SharedArrayBuffer. - Clipboard denied: Copy selects the FEN for manual Ctrl+C / Command+C instead. - Do not launch index.html via file://; modules and workers need an HTTP(S) server. - Do not install this package in a subdirectory without adjusting root-relative URLs. 7. HOSTING SECURITY NOTES The .htaccess keeps directory listing disabled, denies hidden paths except .well-known, blocks common secret/backup files, enforces HTTPS, and retains security headers. ACME and PKI validation URLs are exempt from HTTPS redirection so AutoSSL can validate over HTTP; other protection rules remain in force. Check the next AutoSSL run in cPanel. Do not upload .env, .git, credentials, logs, or private backups. All runtime code is self-hosted. No CDN allowances or blob workers are needed. Local browser tests used the deployment CSP and real Stockfish WASM. Actual Namecheap/LiteSpeed directives, certificate renewal, and public HTTPS delivery must be checked after upload; this project has not been deployed to your server.