Automatic.css

United States · automaticcss.com · 25 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 25 sub-vendors.

Insights

Last updated 2026-08-16 · revision 7

25 direct vendors, 249 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Automatic.css exhibits low migration readiness. The primary challenge stems from its internal tech stack, which is built on a traditional WordPress/Bricks Builder/Easy Digital Downloads ecosystem. This represents a more monolithic architecture that is not inherently cloud-native, containerized, or microservices-based, making a transition to modern cloud environments a significant and complex undertaking. The absence of revenue data prevents an assessment of the company's financial capacity to fund such a potentially costly migration. Furthermore, unaddressed GDPR compliance adds complexity, particularly regarding data transfer mechanisms and processing locations, which would need careful consideration during any migration involving EU customer data. There is also a degree of platform lock-in to the WordPress and Easy Digital Downloads ecosystem for their own operational infrastructure (website, e-commerce, licensing). While the company's expertise in modern front-end development practices (SCSS, CSS variables, design tokens) suggests a team capable of adopting modern workflows, and the core product itself (a CSS framework) is not a complex backend service, these opportunities are overshadowed by the architectural and financial uncertainties. No specific data residency requirements beyond general GDPR considerations were identified.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

Automatic.css is a US-headquartered company (HQ: United States) selling a commercial software product (CSS framework for WordPress) globally, including to customers in the EU/EEA. As a SaaS/digital product vendor with a global customer base, it almost certainly collects personal data (names, email addresses, payment information) from EU/EEA residents during account registration, licensing, and support interactions. This triggers GDPR applicability under Article 3(2) (extra-territorial scope). The risk level is Medium rather than High because: (1) the company is a small software tool vendor, not a large data processor; (2) the nature of data collected is relatively limited (account/transactional data, not sensitive categories); (3) enforcement actions against small US-based SaaS vendors exist but are less frequent than against large platforms. However, the absence of a visible GDPR-specific compliance statement, a named Data Protection Officer (DPO), or a published Data Processing Agreement (DPA) increases risk. The privacy policy is dynamically loaded via Termageddon (a third-party policy generator), which suggests a basic compliance posture rather than a mature GDPR program.

Evidence: https://automaticcss.com/policies/privacy-policy/, https://automaticcss.com/policies/terms-of-service/, https://automaticcss.com

PCI DSS (source) — Assessment Required

Automatic.css sells software licenses through its website (https://automaticcss.com/pricing/), which involves processing payment card transactions. PCI DSS applies to any entity that stores, processes, or transmits cardholder data. The risk level is Medium because: (1) if Automatic.css uses a fully hosted payment processor (e.g., Stripe, PayPal) that handles all card data without the card data touching Automatic.css servers, the PCI DSS scope is significantly reduced (SAQ A level); (2) however, if any card data flows through their systems, full PCI DSS compliance is required; (3) the website uses Easy Digital Downloads (EDD CFM v2.3.0 meta-generator tag), a WordPress e-commerce plugin, which typically integrates with third-party payment gateways. The risk is that EDD configurations vary and the actual payment data flow is unknown.

Evidence: https://automaticcss.com/pricing/, https://automaticcss.com/policies/privacy-policy/

US State Privacy Laws — Assessment Required

Multiple US states have enacted comprehensive privacy laws modeled after CCPA/GDPR. As a US-based software company with a global customer base including US residents across multiple states, Automatic.css may be subject to one or more state privacy laws depending on the volume of residents' data processed and revenue thresholds. Risk is Low-to-Medium because: (1) the company's small size makes it less likely to meet most state thresholds; (2) enforcement of these newer state laws is still maturing; (3) however, the cumulative compliance burden across multiple state laws is growing.

Evidence: https://automaticcss.com/policies/privacy-policy/

Financials

Three-year financials

Financial Resilience Score: 6/10

Automatic.css exhibits qualitative hallmarks of a healthy niche SaaS business: an annual recurring subscription model with three straightforward tiers ($79/$99/$149), high software gross margins, and a low fixed cost base supported by a small ~9-person mostly-remote team. The founder's large YouTube audience serves as a low-cost customer acquisition channel, and deep integration with popular WordPress page builders (Bricks, Etch, Gutenberg, GeneratePress) creates ecosystem lock-in, while the companion product Frames offers cross-sell potential. However, the company is small, privately held, and does not publish audited financials, limiting external visibility into solvency and profitability. Resilience is materially constrained by key-person risk around founder Kevin Geary, platform concentration risk on the WordPress ecosystem, and competitive pressure from Tailwind CSS and free/open-source alternatives. The license model allows continued plugin use after cancellation (losing only updates/support), which may weaken renewal incentives. On balance, the business appears operationally sound but lacks the scale and diversification of larger SaaS peers.

Key strengths: Recurring annual subscription revenue model, Low fixed cost base with small ~9-person team, Strong brand and community moat in WordPress ecosystem, Founder-led low-cost customer acquisition via YouTube, Ecosystem lock-in via page builder integrations, Cross-sell opportunity with Frames companion product

Risk factors: Single-founder / key-person risk (Kevin Geary), Platform concentration risk on WordPress ecosystem, Competitive pressure from Tailwind CSS and open-source alternatives, Small scale with likely low-single-digit-millions revenue, No disclosed audited financials, License continues working after cancellation, weakening renewal incentive

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report