About Private Packagist
We build the infrastructure PHP runs on
Private Packagist is a private Composer repository and PHP supply chain security service that gives development teams one trusted source for all their private and open-source PHP packages. It is built by Nils Adermann and Jordi Boggiano, the creators of Composer and Packagist.org, and developed and operated by Packagist Conductors GmbH in Berlin, Germany.
- 800+ companies use Private Packagist
- 60+ countries
- 200B+ installs from Packagist.org since 2012
- 1,000+ Composer contributors
What Private Packagist does
One Composer repository URL for all your packages, available as a cloud service or on your own infrastructure.
Private Packagist Cloud
A managed Composer repository for your organization with a single URL for all your packages. Private packages are loaded directly from GitHub, GitLab, Bitbucket, or any Git, Mercurial, or Subversion repository, and new versions are published automatically when you push a tag. We run the infrastructure, so there is nothing to install or maintain.
See pricingPrivate Packagist Self-Hosted
The same product running on your own infrastructure. With KOTS (Kubernetes Off-The-Shelf), it runs on any Linux server or virtual machine, without a Kubernetes cluster of your own. If you already run Kubernetes, you can install it into your cluster with our Helm chart instead. It is designed for companies whose compliance rules require that source code and packages never leave their network.
Learn about Private Packagist Self-HostedMirroring and Supply Chain Security
Private Packagist mirrors Packagist.org and any other Composer repository, such as Magento Marketplace or Drupal, so installs keep working when GitHub is down or a maintainer deletes a package. Malware-flagged versions are blocked, and you can restrict which Composer plugins may run across your whole organization.
Learn about Supply Chain SecuritySecurity Monitoring
Private Packagist scans the composer.lock files of your projects and alerts you by email, Slack, Microsoft Teams, or webhook when a dependency has a known vulnerability, and tells you which safe version to update to.
Learn about Security MonitoringUpdate Review and Package Usage Tracking
Update Review comments on pull requests with a summary of every composer.lock change, linked to diffs and changelogs. Package Usage Tracking shows which of your applications use a package and at which version.
Package distribution for vendors
Companies that sell PHP software give each customer their own Composer repository URL and token, limited to the packages and versions they paid for. Access expires automatically, and an API connects it to your shop.
Learn about Private Packagist for VendorsSuborganizations for agencies
Agencies and companies with many projects create a separate Composer repository for each client project, with its own packages, tokens, and team access. Client-specific credentials, like Magento Marketplace keys, stay in the right project.
Learn about Private Packagist for AgenciesConductor Early access
Conductor runs composer update in your CI with full plugin and script support, and opens pull requests on GitHub, GitLab, or Bitbucket, grouped and scheduled in ways that make sense for PHP projects. Free for open-source projects through our Open Source Program.
Learn about ConductorWhat makes Private Packagist different
Built and run by the Composer team
We created Composer in 2011 and have run Packagist.org ever since, which has now served over 200 billion package installs. Because we develop Composer, Private Packagist is the first to support new Composer functionality, and we make sure it stays compatible with every Composer release.
Our support answers come from the people who build Composer and know how it behaves in your projects.
| Year | Installs (billions) |
|---|---|
| 2013 | 0.1 |
| 2014 | 0.38 |
| 2015 | 0.97 |
| 2016 | 2.03 |
| 2017 | 3.61 |
| 2018 | 5.2 |
| 2019 | 7.75 |
| 2020 | 12.28 |
| 2021 | 17.97 |
| 2022 | 23.39 |
| 2023 | 24.6 |
| 2024 | 31.03 |
| 2025 | 35.95 |
| 2026 (estimate) | 54.5 |
Made for PHP developers, not adapted from Java tooling
JFrog Artifactory, Cloudsmith, and Sonatype Nexus Repository are generic artifact managers that support Composer as one of many package formats. They carry over workflows from ecosystems like Java, where every library release goes through a build process that creates an archive and pushes it to the repository.
With Private Packagist you release a new version the way PHP developers are used to: you push a Git tag, and Private Packagist picks it up automatically. GitLab's Composer registry is still labeled beta and not ready for production use, and GitHub Packages does not support Composer at all.
Releasing a version with a generic artifact manager
- Commit
- CI build job
- Create archive
- Upload to repository
- Released
Releasing a version with Private Packagist
- Commit
- Push a Git tag
- Released
Instant updates instead of slow rebuilds
Satis, the open-source static repository generator we also maintain, writes all package metadata into static files that you host yourself. Every change to any package means regenerating those files, which gets slow as your repositories grow, and Satis has no per-user access control. Private Packagist updates only what changed as soon as you push, and controls which users and tokens can access which packages.
Compare Satis and Private PackagistSuborganizations that match how agencies work
PHP agencies build many projects for many clients, and Private Packagist reflects that. Each client gets a suborganization with its own Composer repository URL, containing packages you share across all clients as well as packages that belong only to that client. Client-specific credentials and team access stay separate.
Learn about Private Packagist for AgenciesComposer 1.x support until at least 2027
Packagist.org stopped serving metadata to Composer 1.x on September 1, 2025. Private Packagist keeps mirroring for Composer 1.x working until at least September 1, 2027, so legacy applications keep installing while you migrate.
Learn about extended Composer 1.x supportPublished prices and monthly billing
Private Packagist Cloud starts at €59 per month for 3 users. You can pay monthly or annually, cancel at any time, and start with a 14-day free trial without talking to sales. Private Packagist Self-Hosted is billed annually and comes with a 30-day free trial.
See pricingYour subscription funds Composer and Packagist.org
Private Packagist covers more than half of the cost of running, maintaining, and developing Composer and Packagist.org. Every subscription also pays for our Open Source Pledge contributions to the PHP Foundation and other PHP projects.
Who uses Private Packagist
More than 800 companies in over 60 countries use Private Packagist, from teams of three developers to organizations with hundreds of developers.
Digital and e-commerce agencies
Agencies that manage dependencies and access for dozens of client projects on Magento, Adobe Commerce, Shopware, TYPO3, Drupal, and WordPress, such as Vaimo, Smile, Inviqa, Syde, Corra, and Elgentos.
SaaS and internet companies
Companies whose product is built in PHP and shared across many internal packages, such as GetYourGuide, trivago, SurveyMonkey, Brevo, Help Scout, and SmugMug.
Retail and consumer brands
Brands running their own e-commerce and web platforms, such as Pernod Ricard, Lindt & Sprüngli, Helly Hansen, REWE digital, Regatta, Kurt Geiger, and Monin.
Software vendors
Companies that build open-source platforms or sell PHP packages, themes, and extensions to their customers, such as Spryker, Hyvä, Pimcore, Craft CMS, Sylius, TYPO3, and Yoast.
Media and publishing
Publishers and media companies running many sites on shared code, such as Wirecutter, Warner Music Group, Hubert Burda Media, Axel Springer, Future, The Motley Fool, and Springer Nature.
Finance, healthcare, and the public sector
Banks, payment companies, pharma, government departments, and universities with compliance requirements, such as Pfizer, Mollie, Sparekassen Danmark, Innovation, Science and Economic Development Canada, the Australian Government DEWR, and Texas A&M University.
Enterprises across industries also rely on Private Packagist, including Canon, Wipro, UL Solutions, Arcadis, Ipsos, ASSA ABLOY, and RS Group.
The team behind Private Packagist
Nils Adermann and Jordi Boggiano started Composer together in April 2011 and launched Packagist.org that summer. For years, Jordi ran Packagist.org on a personal server, paid for out of pocket, while both of them maintained Composer in their spare time.
In July 2016 they founded Packagist Conductors to put Composer and Packagist.org on a sustainable footing, and launched Private Packagist at SymfonyCon in Berlin on December 1, 2016. Its revenue has funded work on Composer and Packagist.org ever since.
Read the full story on our blog: 15 years of Packagist: Over 200 billion package installs.
- 2011 Composer and Packagist.org launch
- 2016 Packagist Conductors founded, Private Packagist launched
- 2017 Self-hosted version for on-premises installs
- 2019 Private Packagist for Vendors, Packagist.org moves to AWS
- 2020 Composer 2.0 and Security Monitoring
- 2021 Update Review
- 2024 Open Source Pledge, Conductor announced
- 2025 Packagist.org transparency log
- 2026 200 billion installs, malware blocking
The team
We are a team of just over ten people. A few of us work from our headquarters in Berlin, and the rest work remotely from Germany, Switzerland, the United Kingdom, Belgium, and Norway.
The company has no outside investment and is funded entirely by customer subscriptions. Every engineer also answers customer support.
How Private Packagist works
-
Sign in
Sign in with GitHub, GitLab, Bitbucket, or an email address and create an organization. Your 14-day trial starts right away.
-
Add your packages
Add your private repositories. Packagist.org is mirrored automatically, and you can add other Composer repositories.
-
Use one URL
Replace your Composer repository configuration with a single URL and give your CI read-only tokens.
-
Release with a tag
Push a Git tag and the new version is available to every project right away.
The documentation covers setup, migration from Satis, and CI integration.
Support
You reach us by email at contact@packagist.com or through the chat on our website. We guarantee a response by the next business day, and during business hours in Europe we often reply within an hour. All support is provided by engineers with their own experience in PHP development.
Status and incidents
We publish incidents and maintenance on status.packagist.com. Private Packagist Cloud runs on AWS in Ireland, with additional mirrors for Composer downloads in the United States and Singapore.
Key facts
| Company name | Packagist Conductors GmbH |
|---|---|
| Product | Private Packagist |
| Type | Private Composer repository and PHP supply chain security service (SaaS and self-hosted) |
| Founded | July 2016 in Berlin. Private Packagist launched on December 1, 2016 |
| Founders | Nils Adermann and Jordi Boggiano, creators of Composer and Packagist.org |
| Headquarters | Friedrichstr. 155, 10117 Berlin, Germany |
| Team | Just over ten people in Germany, Switzerland, the United Kingdom, Belgium, and Norway |
| Funding | Bootstrapped, funded by customer subscriptions, no outside investment |
| Website | packagist.com |
| Core offering | A single trusted Composer repository for private packages and mirrored open-source dependencies, with malware blocking, security monitoring, and access control |
| Products | Private Packagist Cloud, Private Packagist Self-Hosted, Private Packagist for Vendors, Conductor (early access) |
| Pricing | Cloud from €59 per month including 3 users, extra users €17 per month. Self-Hosted from €3,900 per year including 10 users. Full pricing |
| Contract terms | Cloud: monthly or annual billing, cancel anytime. Self-Hosted: annual contract |
| Free trial | 14 days for Cloud, 30 days for Self-Hosted |
| Integrations | GitHub, GitHub Enterprise Server, GitLab.com, GitLab Self-Managed, Bitbucket Cloud, Bitbucket Data Center, Azure DevOps, AWS CodeCommit, Slack, Microsoft Teams, webhooks, REST API |
| Hosting | AWS in Ireland, with Composer download mirrors in the United States and Singapore |
| Support | Email and chat, answered by engineers, next business day response guaranteed |
| Notable customers | Pfizer, Canon, Warner Music Group, SurveyMonkey, trivago, GetYourGuide, Springer Nature, Lindt & Sprüngli, TYPO3, Yoast, Sylius, Spryker |
| Customers served | 800+ companies in 60+ countries |
| Open-source work | Composer (over 1,000 contributors) and Packagist.org (over 200 billion installs) |
| Alternatives | Satis, JFrog Artifactory, Cloudsmith, Sonatype Nexus Repository, GitLab package registry |
| Contact | contact@packagist.com |
| Social | LinkedIn · Mastodon · Bluesky · X · GitHub · Blog |
Frequently asked questions
How is Private Packagist related to Packagist.org and Composer?
All three are built by the same team. Composer is the open-source PHP dependency manager, Packagist.org is the free public package repository, and Private Packagist is the commercial product for private packages and companies' dependency management. Private Packagist revenue funds Composer and Packagist.org.
Can I run Private Packagist on my own servers?
Yes. Private Packagist Self-Hosted runs on any Linux server or virtual machine with KOTS, or in your existing Kubernetes cluster with our Helm chart. We recommend the cloud version unless your compliance requirements rule it out, because we handle updates, backups, and availability for you.
How is Private Packagist different from Satis?
Satis generates a static Composer repository that you have to host and rebuild yourself. Private Packagist updates automatically when you push, controls which users and tokens can access which packages, mirrors your dependencies, and monitors them for security issues. See the full comparison.
Why not use Artifactory, Nexus, or GitLab for Composer packages?
Generic artifact managers treat Composer as one format among many and expect release workflows from other ecosystems. Private Packagist reads packages straight from your Git repositories and includes Composer-specific features like Update Review and Security Monitoring of composer.lock files. Your subscription also directly pays for the maintenance and development of Composer and Packagist.org.
Where is my data stored?
Private Packagist Cloud runs on AWS in Ireland, with additional mirrors for Composer downloads in the United States and Singapore. All subprocessors are covered by data processing agreements.
Is there a free trial?
Yes. Private Packagist Cloud has a 14-day free trial and Private Packagist Self-Hosted a 30-day free trial. Your card is charged only after the trial ends, and we can extend it on request.
Is Private Packagist free for open-source projects?
Open-source projects can use Packagist.org for free. Non-profit organizations and educational institutions get a 25% discount on Private Packagist, and Conductor is free for open-source projects through its Open Source Program.
How do I report a security vulnerability?
Send the details to contact@packagist.com. We run a bug bounty program for packagist.com and repo.packagist.com.
Contact
Packagist Conductors GmbH is registered in Berlin, Germany. Legal details are in our imprint, and our logos are available on the brand assets page. If you have any questions or feedback, email us at contact@packagist.com or chat with us.
Start Free Trial
Login to create an organization and start your free trial!