Linking Packagist as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Packagist connector syncs packages, versions, downloads, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
None. The Packagist API is public, so no account or API key is needed.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Pull metadata, download statistics, and security advisories for PHP packages from Packagist (the Composer package registry).
Packagist's read APIs are public, so no credentials are required. Enter the packages you want to track, one per line (or comma-separated), as vendor/package names. A bare vendor name syncs every package published by that vendor. For example:
Download statistics sync incrementally per day; the other tables sync as a full refresh.
You'll be asked for:
- Packages: for example
monolog/monolog symfony/console yourvendor.
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
Some Packagist tables sync incrementally, so later runs only fetch new or updated rows. The rest are full refresh.
Configuration
| Option | Type | Required |
|---|---|---|
Packages | textarea | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
packages | Package metadata: one row per configured package with description, type, repository, download totals, GitHub stats, and maintainers. | Full refresh | — | — |
versions | Package versions: one row per released version (and dev branch) of each configured package, with dependencies, dist/source links, and license. | Full refresh | — | — |
downloads | Daily download statistics: one row per configured package per day. | Incremental, Full refresh | date | — |
security_advisories | Security advisories affecting the configured packages, as reported by the Packagist security advisories API. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the API key is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.