About Private Packagist

We build the infrastructure PHP runs on

Private Packagist is a private Composer repository and PHP supply chain security service that gives development teams one trusted source for all their private and open-source PHP packages. It is built by Nils Adermann and Jordi Boggiano, the creators of Composer and Packagist.org, and developed and operated by Packagist Conductors GmbH in Berlin, Germany.

  • 800+ companies use Private Packagist
  • 60+ countries
  • 200B+ installs from Packagist.org since 2012
  • 1,000+ Composer contributors

What Private Packagist does

One Composer repository URL for all your packages, available as a cloud service or on your own infrastructure.

Private Packagist Cloud

A managed Composer repository for your organization with a single URL for all your packages. Private packages are loaded directly from GitHub, GitLab, Bitbucket, or any Git, Mercurial, or Subversion repository, and new versions are published automatically when you push a tag. We run the infrastructure, so there is nothing to install or maintain.

See pricing

Private Packagist Self-Hosted

The same product running on your own infrastructure. With KOTS (Kubernetes Off-The-Shelf), it runs on any Linux server or virtual machine, without a Kubernetes cluster of your own. If you already run Kubernetes, you can install it into your cluster with our Helm chart instead. It is designed for companies whose compliance rules require that source code and packages never leave their network.

Learn about Private Packagist Self-Hosted

Mirroring and Supply Chain Security

Private Packagist mirrors Packagist.org and any other Composer repository, such as Magento Marketplace or Drupal, so installs keep working when GitHub is down or a maintainer deletes a package. Malware-flagged versions are blocked, and you can restrict which Composer plugins may run across your whole organization.

Learn about Supply Chain Security

Security Monitoring

Private Packagist scans the composer.lock files of your projects and alerts you by email, Slack, Microsoft Teams, or webhook when a dependency has a known vulnerability, and tells you which safe version to update to.

Learn about Security Monitoring

Update Review and Package Usage Tracking

Update Review comments on pull requests with a summary of every composer.lock change, linked to diffs and changelogs. Package Usage Tracking shows which of your applications use a package and at which version.

Package distribution for vendors

Companies that sell PHP software give each customer their own Composer repository URL and token, limited to the packages and versions they paid for. Access expires automatically, and an API connects it to your shop.

Learn about Private Packagist for Vendors

Suborganizations for agencies

Agencies and companies with many projects create a separate Composer repository for each client project, with its own packages, tokens, and team access. Client-specific credentials, like Magento Marketplace keys, stay in the right project.

Learn about Private Packagist for Agencies

Conductor Early access

Conductor runs composer update in your CI with full plugin and script support, and opens pull requests on GitHub, GitLab, or Bitbucket, grouped and scheduled in ways that make sense for PHP projects. Free for open-source projects through our Open Source Program.

Learn about Conductor

What makes Private Packagist different

Built and run by the Composer team

We created Composer in 2011 and have run Packagist.org ever since, which has now served over 200 billion package installs. Because we develop Composer, Private Packagist is the first to support new Composer functionality, and we make sure it stays compatible with every Composer release.

Our support answers come from the people who build Composer and know how it behaves in your projects.

Installs from Packagist.org per year, in billions. The 2026 figure is an estimate based on January to September.
Yearly installs from Packagist.org grew from 0.1 billion in 2013 to 36 billion in 2025, and an estimated 55 billion in 2026. 0 20B 40B 60B Private Packagist launched 2013: 0.1 billion installs 2014: 0.4 billion installs 2014 2015: 1.0 billion installs 2016: 2.0 billion installs 2017: 3.6 billion installs 2017 2018: 5.2 billion installs 2019: 7.8 billion installs 2020: 12.3 billion installs 2020 2021: 18.0 billion installs 2022: 23.4 billion installs 2023: 24.6 billion installs 2023 2024: 31.0 billion installs 2025: 36.0 billion installs 2026 (estimate): 54.5 billion installs 2026 ~55B est.
Installs from Packagist.org per year
YearInstalls (billions)
20130.1
20140.38
20150.97
20162.03
20173.61
20185.2
20197.75
202012.28
202117.97
202223.39
202324.6
202431.03
202535.95
2026 (estimate)54.5

Made for PHP developers, not adapted from Java tooling

JFrog Artifactory, Cloudsmith, and Sonatype Nexus Repository are generic artifact managers that support Composer as one of many package formats. They carry over workflows from ecosystems like Java, where every library release goes through a build process that creates an archive and pushes it to the repository.

With Private Packagist you release a new version the way PHP developers are used to: you push a Git tag, and Private Packagist picks it up automatically. GitLab's Composer registry is still labeled beta and not ready for production use, and GitHub Packages does not support Composer at all.

Releasing a version with a generic artifact manager

  1. Commit
  2. CI build job
  3. Create archive
  4. Upload to repository
  5. Released

Releasing a version with Private Packagist

  1. Commit
  2. Push a Git tag
  3. Released

Instant updates instead of slow rebuilds

Satis, the open-source static repository generator we also maintain, writes all package metadata into static files that you host yourself. Every change to any package means regenerating those files, which gets slow as your repositories grow, and Satis has no per-user access control. Private Packagist updates only what changed as soon as you push, and controls which users and tokens can access which packages.

Compare Satis and Private Packagist

Suborganizations that match how agencies work

PHP agencies build many projects for many clients, and Private Packagist reflects that. Each client gets a suborganization with its own Composer repository URL, containing packages you share across all clients as well as packages that belong only to that client. Client-specific credentials and team access stay separate.

Learn about Private Packagist for Agencies

Composer 1.x support until at least 2027

Packagist.org stopped serving metadata to Composer 1.x on September 1, 2025. Private Packagist keeps mirroring for Composer 1.x working until at least September 1, 2027, so legacy applications keep installing while you migrate.

Learn about extended Composer 1.x support

Published prices and monthly billing

Private Packagist Cloud starts at €59 per month for 3 users. You can pay monthly or annually, cancel at any time, and start with a 14-day free trial without talking to sales. Private Packagist Self-Hosted is billed annually and comes with a 30-day free trial.

See pricing

Your subscription funds Composer and Packagist.org

Private Packagist covers more than half of the cost of running, maintaining, and developing Composer and Packagist.org. Every subscription also pays for our Open Source Pledge contributions to the PHP Foundation and other PHP projects.

800+ companies subscribe to Private Packagist
Private Packagist
Composer development and maintenance
Packagist.org hosting and operations
PHP Foundation and more through the Open Source Pledge

Who uses Private Packagist

More than 800 companies in over 60 countries use Private Packagist, from teams of three developers to organizations with hundreds of developers.

Digital and e-commerce agencies

20 to 2,000 employees

Agencies that manage dependencies and access for dozens of client projects on Magento, Adobe Commerce, Shopware, TYPO3, Drupal, and WordPress, such as Vaimo, Smile, Inviqa, Syde, Corra, and Elgentos.

SaaS and internet companies

100 to 2,000 employees

Companies whose product is built in PHP and shared across many internal packages, such as GetYourGuide, trivago, SurveyMonkey, Brevo, Help Scout, and SmugMug.

Retail and consumer brands

600 to 20,000 employees

Brands running their own e-commerce and web platforms, such as Pernod Ricard, Lindt & Sprüngli, Helly Hansen, REWE digital, Regatta, Kurt Geiger, and Monin.

Software vendors

20 to 500 employees

Companies that build open-source platforms or sell PHP packages, themes, and extensions to their customers, such as Spryker, Hyvä, Pimcore, Craft CMS, Sylius, TYPO3, and Yoast.

Media and publishing

500 to 20,000 employees

Publishers and media companies running many sites on shared code, such as Wirecutter, Warner Music Group, Hubert Burda Media, Axel Springer, Future, The Motley Fool, and Springer Nature.

Finance, healthcare, and the public sector

1,000 to 80,000 employees

Banks, payment companies, pharma, government departments, and universities with compliance requirements, such as Pfizer, Mollie, Sparekassen Danmark, Innovation, Science and Economic Development Canada, the Australian Government DEWR, and Texas A&M University.

Enterprises across industries also rely on Private Packagist, including Canon, Wipro, UL Solutions, Arcadis, Ipsos, ASSA ABLOY, and RS Group.

Pfizer Logo
Canon Logo
Warner Music Group Logo
SurveyMonkey Logo
trivago Logo
GetYourGuide Logo
Springer Nature Logo
Lindt & Sprüngli Logo
TYPO3 Logo
Yoast Logo
Sylius Logo
Spryker Logo
Inviqa Logo
Syde Logo
Australian Government: Department of Employment and Workplace Relations Logo

The team behind Private Packagist

Nils Adermann and Jordi Boggiano started Composer together in April 2011 and launched Packagist.org that summer. For years, Jordi ran Packagist.org on a personal server, paid for out of pocket, while both of them maintained Composer in their spare time.

In July 2016 they founded Packagist Conductors to put Composer and Packagist.org on a sustainable footing, and launched Private Packagist at SymfonyCon in Berlin on December 1, 2016. Its revenue has funded work on Composer and Packagist.org ever since.

Read the full story on our blog: 15 years of Packagist: Over 200 billion package installs.

  1. 2011 Composer and Packagist.org launch
  2. 2016 Packagist Conductors founded, Private Packagist launched
  3. 2017 Self-hosted version for on-premises installs
  4. 2019 Private Packagist for Vendors, Packagist.org moves to AWS
  5. 2020 Composer 2.0 and Security Monitoring
  6. 2021 Update Review
  7. 2024 Open Source Pledge, Conductor announced
  8. 2025 Packagist.org transparency log
  9. 2026 200 billion installs, malware blocking
Nils Adermann

Nils Adermann, Co-Founder

Nils is co-creator of Composer and managing director of Packagist Conductors. He was a founding board member of the PHP Foundation.

Jordi Boggiano

Jordi Boggiano, Co-Founder

Jordi is co-creator and lead maintainer of Composer, and runs Packagist.org. He is also the author of Monolog, one of the most installed PHP packages, and managing director of Packagist Conductors.

The team

We are a team of just over ten people. A few of us work from our headquarters in Berlin, and the rest work remotely from Germany, Switzerland, the United Kingdom, Belgium, and Norway.

The company has no outside investment and is funded entirely by customer subscriptions. Every engineer also answers customer support.

The Private Packagist team celebrating 10 years of Private Packagist in Berlin
Celebrating 10 years of Private Packagist, Berlin, September 2026
The Private Packagist team on a rooftop
Zürich, April 2024
The Private Packagist team under a cherry tree in Hamburg
Hamburg, March 2025
The Private Packagist team on a rooftop in front of St Paul's Cathedral in London
London, April 2026

How Private Packagist works

  1. Sign in

    Sign in with GitHub, GitLab, Bitbucket, or an email address and create an organization. Your 14-day trial starts right away.

  2. Add your packages

    Add your private repositories. Packagist.org is mirrored automatically, and you can add other Composer repositories.

  3. Use one URL

    Replace your Composer repository configuration with a single URL and give your CI read-only tokens.

  4. Release with a tag

    Push a Git tag and the new version is available to every project right away.

The documentation covers setup, migration from Satis, and CI integration.

Support

You reach us by email at contact@packagist.com or through the chat on our website. We guarantee a response by the next business day, and during business hours in Europe we often reply within an hour. All support is provided by engineers with their own experience in PHP development.

Status and incidents

We publish incidents and maintenance on status.packagist.com. Private Packagist Cloud runs on AWS in Ireland, with additional mirrors for Composer downloads in the United States and Singapore.

Key facts

Company namePackagist Conductors GmbH
ProductPrivate Packagist
TypePrivate Composer repository and PHP supply chain security service (SaaS and self-hosted)
FoundedJuly 2016 in Berlin. Private Packagist launched on December 1, 2016
FoundersNils Adermann and Jordi Boggiano, creators of Composer and Packagist.org
HeadquartersFriedrichstr. 155, 10117 Berlin, Germany
TeamJust over ten people in Germany, Switzerland, the United Kingdom, Belgium, and Norway
FundingBootstrapped, funded by customer subscriptions, no outside investment
Websitepackagist.com
Core offeringA single trusted Composer repository for private packages and mirrored open-source dependencies, with malware blocking, security monitoring, and access control
ProductsPrivate Packagist Cloud, Private Packagist Self-Hosted, Private Packagist for Vendors, Conductor (early access)
PricingCloud from €59 per month including 3 users, extra users €17 per month. Self-Hosted from €3,900 per year including 10 users. Full pricing
Contract termsCloud: monthly or annual billing, cancel anytime. Self-Hosted: annual contract
Free trial14 days for Cloud, 30 days for Self-Hosted
IntegrationsGitHub, GitHub Enterprise Server, GitLab.com, GitLab Self-Managed, Bitbucket Cloud, Bitbucket Data Center, Azure DevOps, AWS CodeCommit, Slack, Microsoft Teams, webhooks, REST API
HostingAWS in Ireland, with Composer download mirrors in the United States and Singapore
SupportEmail and chat, answered by engineers, next business day response guaranteed
Notable customersPfizer, Canon, Warner Music Group, SurveyMonkey, trivago, GetYourGuide, Springer Nature, Lindt & Sprüngli, TYPO3, Yoast, Sylius, Spryker
Customers served800+ companies in 60+ countries
Open-source workComposer (over 1,000 contributors) and Packagist.org (over 200 billion installs)
AlternativesSatis, JFrog Artifactory, Cloudsmith, Sonatype Nexus Repository, GitLab package registry
Contactcontact@packagist.com
Social LinkedIn · Mastodon · Bluesky · X · GitHub · Blog

Frequently asked questions

How is Private Packagist related to Packagist.org and Composer?

All three are built by the same team. Composer is the open-source PHP dependency manager, Packagist.org is the free public package repository, and Private Packagist is the commercial product for private packages and companies' dependency management. Private Packagist revenue funds Composer and Packagist.org.

Can I run Private Packagist on my own servers?

Yes. Private Packagist Self-Hosted runs on any Linux server or virtual machine with KOTS, or in your existing Kubernetes cluster with our Helm chart. We recommend the cloud version unless your compliance requirements rule it out, because we handle updates, backups, and availability for you.

How is Private Packagist different from Satis?

Satis generates a static Composer repository that you have to host and rebuild yourself. Private Packagist updates automatically when you push, controls which users and tokens can access which packages, mirrors your dependencies, and monitors them for security issues. See the full comparison.

Why not use Artifactory, Nexus, or GitLab for Composer packages?

Generic artifact managers treat Composer as one format among many and expect release workflows from other ecosystems. Private Packagist reads packages straight from your Git repositories and includes Composer-specific features like Update Review and Security Monitoring of composer.lock files. Your subscription also directly pays for the maintenance and development of Composer and Packagist.org.

Where is my data stored?

Private Packagist Cloud runs on AWS in Ireland, with additional mirrors for Composer downloads in the United States and Singapore. All subprocessors are covered by data processing agreements.

Is there a free trial?

Yes. Private Packagist Cloud has a 14-day free trial and Private Packagist Self-Hosted a 30-day free trial. Your card is charged only after the trial ends, and we can extend it on request.

Is Private Packagist free for open-source projects?

Open-source projects can use Packagist.org for free. Non-profit organizations and educational institutions get a 25% discount on Private Packagist, and Conductor is free for open-source projects through its Open Source Program.

How do I report a security vulnerability?

Send the details to contact@packagist.com. We run a bug bounty program for packagist.com and repo.packagist.com.

Contact

Packagist Conductors GmbH is registered in Berlin, Germany. Legal details are in our imprint, and our logos are available on the brand assets page. If you have any questions or feedback, email us at contact@packagist.com or chat with us.

Start Free Trial

Login to create an organization and start your free trial!