AccessPress Themes
Nepal · accesspressthemes.com · 4 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 4
- Financial Resilience: 5
Technology vendors
- Amazon Web Services (aws) — Technology — United States
- Netlify, Inc. — Technology — United States
- WP Rocket — Technology — France
- and 1 more
Services catalogue
1 service in catalogue across 1 category; runs on 4 sub-vendors.
- Everest Timeline
Insights
Last updated 2026-07-21 · revision 2
4 direct vendors, 119 subvendors
Direct vendors by controlling owner country (sample)
- United States: 3
- France: 1
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Cyprus: 1
- Germany: 2
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
AccessPress Themes demonstrates low migration readiness. The core technology stack, heavily reliant on WordPress, PHP, and associated page builders (Elementor, WPBakery), represents a traditional, monolithic architecture. This setup is not cloud-native, containerized, or based on microservices, meaning a migration to a modern cloud environment would likely require substantial re-platforming and re-engineering rather than a straightforward lift-and-shift. This deep integration with the WordPress ecosystem creates significant platform lock-in. The absence of data regarding financial stability (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially complex and costly migration effort. While no specific data residency requirements or regulatory environments are specified, which could simplify some aspects, the fundamental architectural challenges and financial unknowns are major impediments to high migration readiness. Vendor lock-in risk for specific services is unknown, but the overarching platform lock-in is high.
Compliance
6 in-scope frameworks identified; showing 3.
WordPress.org — Assessment Required
AccessPress Themes distributes products through WordPress.org, ThemeForest, and CodeCanyon. Following the 2022 supply chain compromise, WordPress.org temporarily removed AccessPress products from its repository. Platform compliance is HIGH risk because: (1) delisting from WordPress.org or Envato marketplaces would be commercially devastating given 360,000+ active installs; (2) Envato's Author Terms require security standards, privacy compliance, and responsible disclosure; (3) WordPress.org's plugin review team has strict security and privacy requirements; (4) recurring security incidents could result in permanent delisting.
Evidence: https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/, https://wordpress.org/plugins/, https://themeforest.net/user/accesskeys, https://codecanyon.net/user/accesskeys
PCI DSS (source) — Assessment Required
AccessPress Themes sells premium themes and plugins directly and through marketplaces. If they process payment card data directly on their website (rather than fully delegating to a PCI-compliant payment processor), PCI DSS obligations apply. Risk is MEDIUM because: (1) if using fully hosted payment processors (Stripe, PayPal), PCI scope is minimal (SAQ A); (2) if any card data touches their servers, full PCI DSS compliance is required; (3) the 2022 security breach raises questions about whether payment data was exposed.
Evidence: https://accesspressthemes.com, https://www.pcisecuritystandards.org/, https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/
ISO 27001 (source) — Assessment Required
The 2021–2022 supply chain security incident — where AccessPress Themes' entire plugin and theme repository was compromised with a backdoor affecting 360,000+ websites — represents a catastrophic information security failure. ISO 27001 certification would require a comprehensive ISMS (Information Security Management System) covering asset management, access control, cryptography, supplier security, incident management, and business continuity. The absence of any ISO 27001 certification, combined with the documented supply chain breach, indicates HIGH risk. The reputational and legal consequences of the breach (potential GDPR violations, customer trust erosion, WordPress.org delisting of products) further elevate this risk level. Enterprise customers and marketplace platforms (ThemeForest, CodeCanyon) may increasingly require ISO 27001 or equivalent assurance.
Evidence: https://accesspressthemes.com, https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/, https://www.iso.org/isoiec-27001-information-security.html
Financials
Three-year financials
- null:
Financial Resilience Score: 5/10
AccessPress Themes is a privately held Nepali WordPress theme and plugin developer with no public financial disclosures available. Nepal's Office of the Company Registrar does not publish private company accounts online, the company is not listed on NEPSE or any other exchange, and it has no SEC filings. As such, revenue, EBIT, and equity cannot be verified from primary sources. Despite the lack of financial transparency, the company demonstrates qualitative signs of resilience: a ~10+ year operating history, a diversified catalogue of 64 themes and 109 plugins, 360,000+ active installs, and Elite author status on Envato CodeCanyon. The freemium funnel via WordPress.org drives low-CAC discovery, and USD-denominated revenue against a Nepal-based cost structure supports margins and provides a natural FX hedge against NPR depreciation. However, significant risks exist: heavy dependence on the WordPress ecosystem, marketplace concentration on Envato/CodeCanyon, competitive pressure from well-funded theme houses (Divi, Astra, Kadence), potential AI-driven disruption of pre-built theme demand, and country risks including political instability and international payment friction from Nepal. Without visibility into cash reserves, debt, or profitability, a mid-range resilience score is appropriate.
Key strengths: 10+ year operating history in WordPress ecosystem, Diversified catalogue: 64 themes and 109 plugins, 360,000+ active website installs, Elite author status on Envato CodeCanyon, Freemium funnel via WordPress.org drives low-CAC discovery, USD-denominated revenue with Nepal-based cost structure (favorable margins), Natural FX hedge against NPR depreciation
Risk factors: Platform concentration on WordPress ecosystem, Marketplace dependency on Envato/CodeCanyon commissions and terms, Competitive pressure from Divi, Kadence, Astra/Brainstorm Force, and top ThemeForest authors, Small private company with no financial disclosure, Country risk: Nepal political instability, banking/FX controls, payment friction, AI code-generation tools may reduce demand for pre-built themes
Revenue by geography
- North America and Europe (USD/EUR-weighted, unspecified split): 0%
Revenue by product/service
- WordPress Themes (64 items): 0%
- WordPress Plugins (109 items): 0%
Workforce by country
- Nepal: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.