AccessPress Themes

Nepal · accesspressthemes.com · 4 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 4 sub-vendors.

Insights

Last updated 2026-07-21 · revision 2

4 direct vendors, 119 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

AccessPress Themes demonstrates low migration readiness. The core technology stack, heavily reliant on WordPress, PHP, and associated page builders (Elementor, WPBakery), represents a traditional, monolithic architecture. This setup is not cloud-native, containerized, or based on microservices, meaning a migration to a modern cloud environment would likely require substantial re-platforming and re-engineering rather than a straightforward lift-and-shift. This deep integration with the WordPress ecosystem creates significant platform lock-in. The absence of data regarding financial stability (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially complex and costly migration effort. While no specific data residency requirements or regulatory environments are specified, which could simplify some aspects, the fundamental architectural challenges and financial unknowns are major impediments to high migration readiness. Vendor lock-in risk for specific services is unknown, but the overarching platform lock-in is high.

Compliance

6 in-scope frameworks identified; showing 3.

WordPress.org — Assessment Required

AccessPress Themes distributes products through WordPress.org, ThemeForest, and CodeCanyon. Following the 2022 supply chain compromise, WordPress.org temporarily removed AccessPress products from its repository. Platform compliance is HIGH risk because: (1) delisting from WordPress.org or Envato marketplaces would be commercially devastating given 360,000+ active installs; (2) Envato's Author Terms require security standards, privacy compliance, and responsible disclosure; (3) WordPress.org's plugin review team has strict security and privacy requirements; (4) recurring security incidents could result in permanent delisting.

Evidence: https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/, https://wordpress.org/plugins/, https://themeforest.net/user/accesskeys, https://codecanyon.net/user/accesskeys

PCI DSS (source) — Assessment Required

AccessPress Themes sells premium themes and plugins directly and through marketplaces. If they process payment card data directly on their website (rather than fully delegating to a PCI-compliant payment processor), PCI DSS obligations apply. Risk is MEDIUM because: (1) if using fully hosted payment processors (Stripe, PayPal), PCI scope is minimal (SAQ A); (2) if any card data touches their servers, full PCI DSS compliance is required; (3) the 2022 security breach raises questions about whether payment data was exposed.

Evidence: https://accesspressthemes.com, https://www.pcisecuritystandards.org/, https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/

ISO 27001 (source) — Assessment Required

The 2021–2022 supply chain security incident — where AccessPress Themes' entire plugin and theme repository was compromised with a backdoor affecting 360,000+ websites — represents a catastrophic information security failure. ISO 27001 certification would require a comprehensive ISMS (Information Security Management System) covering asset management, access control, cryptography, supplier security, incident management, and business continuity. The absence of any ISO 27001 certification, combined with the documented supply chain breach, indicates HIGH risk. The reputational and legal consequences of the breach (potential GDPR violations, customer trust erosion, WordPress.org delisting of products) further elevate this risk level. Enterprise customers and marketplace platforms (ThemeForest, CodeCanyon) may increasingly require ISO 27001 or equivalent assurance.

Evidence: https://accesspressthemes.com, https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/, https://www.iso.org/isoiec-27001-information-security.html

Financials

Three-year financials

Financial Resilience Score: 5/10

AccessPress Themes is a privately held Nepali WordPress theme and plugin developer with no public financial disclosures available. Nepal's Office of the Company Registrar does not publish private company accounts online, the company is not listed on NEPSE or any other exchange, and it has no SEC filings. As such, revenue, EBIT, and equity cannot be verified from primary sources. Despite the lack of financial transparency, the company demonstrates qualitative signs of resilience: a ~10+ year operating history, a diversified catalogue of 64 themes and 109 plugins, 360,000+ active installs, and Elite author status on Envato CodeCanyon. The freemium funnel via WordPress.org drives low-CAC discovery, and USD-denominated revenue against a Nepal-based cost structure supports margins and provides a natural FX hedge against NPR depreciation. However, significant risks exist: heavy dependence on the WordPress ecosystem, marketplace concentration on Envato/CodeCanyon, competitive pressure from well-funded theme houses (Divi, Astra, Kadence), potential AI-driven disruption of pre-built theme demand, and country risks including political instability and international payment friction from Nepal. Without visibility into cash reserves, debt, or profitability, a mid-range resilience score is appropriate.

Key strengths: 10+ year operating history in WordPress ecosystem, Diversified catalogue: 64 themes and 109 plugins, 360,000+ active website installs, Elite author status on Envato CodeCanyon, Freemium funnel via WordPress.org drives low-CAC discovery, USD-denominated revenue with Nepal-based cost structure (favorable margins), Natural FX hedge against NPR depreciation

Risk factors: Platform concentration on WordPress ecosystem, Marketplace dependency on Envato/CodeCanyon commissions and terms, Competitive pressure from Divi, Kadence, Astra/Brainstorm Force, and top ThemeForest authors, Small private company with no financial disclosure, Country risk: Nepal political instability, banking/FX controls, payment friction, AI code-generation tools may reduce demand for pre-built themes

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report