Composer/Packagist

A package and dependency manager for PHP projects

Also known as
composer-packagist

What is Composer/Packagist?

Composer is a PHP dependency management tool that uses a centralized package repository (Packagist.org) to discover and install project dependencies. It supports version control integration, security scanning, and both public and private package repositories.

Independently observed

Composer/Packagist pricing

We don't have Composer/Packagist's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

What Composer/Packagist does

The capabilities that matter for package registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Core
Role
Public registry
Ecosystem
Ecosystem / language
PHP
Deployment
Deployment
Both
Formats
Package formats supported
Single ecosystem
Hosting
Private / scoped packages
Upstream proxy / caching
Resolution
Lockfile / deterministic installs
Workspaces / monorepo
Content-addressable store
-
Supply chain
Supply-chain integrity
Vulnerability / licence scanning
Licensing
Openness
Open-source
Pricing
Pricing model
Free / OSS
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (4)

Independently observed
  • GitHub
  • Git
  • Subversion
  • Mercurial

Security & compliance

Known vulnerabilities: 16 (8 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality

Composer/Packagist FAQ

Common questions about Composer/Packagist, answered from independent, dated evidence.

What is Composer/Packagist?

Composer is a PHP dependency management tool that uses a centralized package repository (Packagist.org) to discover and install project dependencies. It supports version control integration, security scanning, and both public and private package repositories. It is indexed under Package Registries.

Source: https://packagist.org

Is Composer/Packagist free?

Composer/Packagist offers a free tier, so you can start without paying. Pricing changes often, so verify at source before relying on it.

Source: https://packagist.org

What platforms does Composer/Packagist support?

Composer/Packagist supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://packagist.org

Can Composer/Packagist be self-hosted?

Yes. Composer/Packagist can be deployed cloud / SaaS and self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://packagist.org

What does Composer/Packagist integrate with?

We have confirmed 3 integrations for Composer/Packagist, including GitHub, Subversion and Mercurial. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://packagist.org

Is Composer/Packagist open source?

Yes. Composer/Packagist is published under the MIT licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/composer/composer

Composer/Packagist alternatives

Other package registries we track, ranked by the same independent score.

All Composer/Packagist alternatives, ranked →

Compare Composer/Packagist

Side by side against other package registries, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Composer/Packagist, not the verdict.

Balanced composite 61 / 100
medium · 52%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Capabilities810.097.1
Release cadence970.076.6
Dependent projects760.075.2
Security score620.085.0
Development activity430.114.6
Stars840.032.3
Integrations200.051.1
Security posture50.180.0-
Package downloads00.150.0-
Developer Q&A activity00.050.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d22mediumsource · 2026-09-10 · 65%

Adoption

AttributeValueEvidence
Dependent repos35,414highsource · 2026-09-10 · 85%
Github stars29,516highsource · 2026-09-10 · 90%

Content

AttributeValueEvidence
Faq6 itemsmediumsource · 2026-09-10 · 66%

Features

AttributeValueEvidence
CapabilitiesRole: public_registry · Ecosystem: php · Deployment: both · Workspaces: Yes · Open source: oss · Pricing model: freemediumsource · 2026-09-10 · 60%

Integrations

AttributeValueEvidence
Count4mediumsource · 2026-08-14 · 60%

Language

AttributeValueEvidence
PrimaryPHPhighsource · 2026-09-10 · 90%

License

AttributeValueEvidence
SpdxMIThighsource · 2026-09-10 · 95%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-14 · 60%
Modelopen_sourcemediumsource · 2026-09-10 · 60%
Price levelfreemediumsource · 2026-09-10 · 60%
TransparentYesmediumsource · 2026-08-03 · 60%

Release

AttributeValueEvidence
History20 itemsmediumsource · 2026-09-10 · 70%
Cadence days6mediumsource · 2026-09-10 · 70%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-03 · 60%

Security

AttributeValueEvidence
Disclosure policyYesmediumsource · 2026-08-14 · 60%
Scorecard6.2highsource · 2026-09-10 · 90%
VulnerabilitiesCount: 16 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=packagist&package_name=composer%2Fcomposer&per_page=100 · Last 12m: 8 · Max severity: HIGHhighsource · 2026-09-10 · 90%
Still deciding?

Is Composer/Packagist the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Composer/Packagist against the rest of the package registries we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Composer/Packagist

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Composer/Packagist up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Composer/Packagist's independent score and links back to this profile.

Composer/Packagist, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/composer-packagist" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/composer-packagist.svg" alt="Composer/Packagist, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Composer/Packagist, verified on vioscaleAI](https://www.vioscale.ai/badge/software/composer-packagist.svg)](https://www.vioscale.ai/software/composer-packagist)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Composer/Packagist. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Composer/Packagist

Not the owner? How vendor profiles work