AnalyticsWP

United States · analyticswp.com · 26 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 26 sub-vendors.

Insights

Last updated 2026-08-14 · revision 3

26 direct vendors, 196 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

AnalyticsWP exhibits low to moderate migration readiness. The primary challenge stems from its core internal tech stack, which is built on WordPress, PHP, and MySQL. This represents a traditional, likely monolithic architecture that is not inherently cloud-native, containerized, or microservices-based. A migration to modern cloud platforms would necessitate substantial re-architecting, refactoring, and development effort, leading to significant costs and complexity. The lack of specified regulatory environment and data residency requirements introduces unknown compliance hurdles that could complicate any migration. Furthermore, the absence of financial stability data makes it impossible to determine the company's capacity to fund such a significant undertaking. While the presence of TypeScript and JavaScript indicates some modern development capabilities, they are unlikely to offset the fundamental architectural challenges. The contradictory vendor data ('Total Vendors: 0' vs. 'Total Services: 27' from diverse countries) adds ambiguity; if the 27 services represent deep integrations, migrating away from them could be complex, despite the geographic diversity. If 'Total Vendors: 0' is accurate, it would imply minimal vendor lock-in, which is a positive for readiness, but the overall architectural challenges remain dominant.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is an international standard for Information Security Management Systems (ISMS). It is not legally mandatory but is increasingly expected by enterprise customers and in regulated industries. AnalyticsWP is a small, early-stage software company (Solid Plugins) with a privacy-by-design product architecture. No ISO 27001 certification has been found. Risk is Low because: (1) the company is small and not in a regulated sector requiring mandatory ISO 27001; (2) the product's local-storage architecture limits information security risk exposure; (3) the company's customer base appears to be primarily SMBs and individual WordPress developers who are unlikely to mandate ISO 27001 certification. Risk would increase if the company targets enterprise or government clients.

Evidence: https://analyticswp.com/gdpr/, https://www.iso.org/isoiec-27001-information-security.html

SOC 2 (source) — Assessment Required

SOC 2 (System and Organization Controls 2) is a voluntary framework relevant to service organizations that store, process, or transmit customer data in the cloud. AnalyticsWP's core architectural design explicitly avoids cloud data storage — all analytics data is stored locally on the customer's own WordPress server, with no data transmitted to AnalyticsWP's servers. This fundamentally reduces the SOC 2 applicability for the plugin itself. However, AnalyticsWP does operate a SaaS-adjacent business (license management, customer accounts, payment processing via solidaffiliate.com) that involves storing customer personal and payment data. A SOC 2 audit for these business operations could be relevant but is not mandatory. Risk is Low because the core product architecture eliminates the primary SOC 2 concern (third-party cloud data custody), and the company appears to be a small startup unlikely to face enterprise customer SOC 2 audit requirements in the near term.

Evidence: https://analyticswp.com/gdpr/, https://analyticswp.com/features/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

PCI DSS (source) — Assessment Required

PCI DSS applies to any organization that accepts, processes, stores, or transmits cardholder data. AnalyticsWP sells licenses online (at $99–$399 per license) and processes payments through its checkout at solidaffiliate.com. The company's payment processing obligations depend on whether it uses a fully outsourced payment processor (e.g., Stripe, PayPal) that handles all cardholder data, or whether it has any direct involvement in card data handling. If using a compliant third-party processor with no direct card data access, PCI DSS obligations are minimal (SAQ A level). Risk is Medium because: (1) e-commerce payment processing is confirmed; (2) the specific payment processor and PCI DSS compliance level are unknown; (3) non-compliance with PCI DSS can result in fines, card brand penalties, and loss of payment processing privileges.

Evidence: https://analyticswp.com/pricing/, https://www.pcisecuritystandards.org/document_library/

Financials

Three-year financials

Financial Resilience Score: 4/10

AnalyticsWP is a young, privately held US micro-SaaS operated by Solid Plugins with no public financial disclosures. Qualitatively, the business benefits from the attractive economics of a WordPress plugin: near-zero marginal cost per license, high gross margins (typically 80-95% for such products), and no server/hosting infrastructure costs since data is stored on the customer's own WordPress site. This creates favorable unit economics compared with SaaS analytics competitors like Fathom or Plausible. However, the business faces significant resilience risks that offset these strengths. It is a very small, single-product, single-platform operation with heavy founder-dependence (Mike Holubowski) and key-person risk. The 100% dependence on the WordPress ecosystem exposes it to platform governance risks (e.g., the ongoing WP Engine/Automattic tensions). The lifetime license model front-loads cash but creates permanent support obligations without recurring revenue from those customers—a common failure pattern for micro-SaaS. Competition from free/freemium alternatives (Google Analytics, MonsterInsights, Plausible, Fathom) is intense, and the product only launched in late 2023/early 2024, giving it a limited track record. The complete absence of financial transparency is itself a risk factor for counterparties.

Key strengths: High gross margins typical of WordPress plugins (80-95%), Near-zero marginal cost per license sold, No server/hosting infrastructure costs (data stored on customer's WordPress site), Bootstrapped, founder-led lean operation with no external funding pressure, Growing privacy-analytics niche driven by GDPR concerns, Traction with named WordPress industry figures providing testimonials, Lifetime license promotion generates large lump-sum cash inflows

Risk factors: Very small scale with key-person/founder dependency, 100% concentration in single product on single platform (WordPress), Lifetime license model creates permanent support obligations without recurring revenue, Intense competition from free/freemium analytics tools, Early stage with limited track record (launched late 2023/early 2024), No public financial transparency for due diligence, Exposure to WordPress governance risks (WP Engine/Automattic tensions), Placeholder testimonials still visible on site suggests immaturity

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report