Browser-Update.org

Germany · browser-update.org · 5 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 5 sub-vendors.

Insights

Last updated 2026-06-19 · revision 2

5 direct vendors, 94 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Browser-Update.org benefits from a modern and flexible tech stack (Python, Flask, JavaScript) which is generally well-suited for cloud migration. Its open-source product and reliance on standard development tools (npm, GitHub) could also simplify technical migration efforts. However, several critical factors significantly reduce its migration readiness. The most prominent is the unknown financial stability, which directly impacts the ability to fund and execute a migration project. There is also no information regarding regulatory compliance or data residency requirements, which are crucial considerations that could introduce significant complexity and cost to a migration. While the tech stack is modern, there's no indication of cloud-native architectural patterns like containerization or microservices, suggesting a potentially more monolithic structure that might require refactoring. The "Vendor Lock-in Risk" for the external services used (GeoLite2, BrowserStack, Crowdin, GitHub, npm) is unknown, adding another layer of uncertainty to migration planning. These significant unknowns and potential architectural complexities place its migration readiness in the lower-medium range.

Compliance

6 in-scope frameworks identified; showing 3.

German Telemediengesetz — Partially Compliant

Risk is rated High because the TTDSG (which replaced TMG provisions on cookies/tracking in 2021) requires prior informed consent for non-essential cookies and tracking technologies. Browser-Update.org's website explicitly acknowledges use of third-party advertising cookies. The contact page references an opt-out mechanism (aboutads.info) but does not describe a prior consent mechanism (cookie banner/consent management platform). Under TTDSG §25, storing or accessing information on end-user devices (including advertising cookies) requires prior consent. German DPA enforcement (BayLDA for Bavaria) has been active in this area. The Impressum (imprint) is present as required by §5 TMG/DDG, which is a positive compliance indicator.

Evidence: https://browser-update.org/contact.html, https://www.gesetze-im-internet.de/ttdsg/, https://www.baylda.de/

EU ePrivacy Directive — Partially Compliant

Risk is rated Medium because the ePrivacy Directive (implemented in Germany via TTDSG) requires prior consent for non-essential cookies. The website uses third-party advertising cookies, and the described opt-out mechanism (aboutads.info) does not satisfy the opt-in consent requirement. However, the embedded script itself is claimed to be cookie-free and non-tracking, which is a significant positive factor reducing overall risk. The ePrivacy Regulation (proposed replacement) has not yet been adopted, so the Directive remains in force. Enforcement risk is moderate given the small scale of the operation.

Evidence: https://browser-update.org/contact.html, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058, https://curia.europa.eu/juris/document/document.jsf?docid=218462&doclang=EN

ISO 27001 (source) — Assessment Required

ISO 27001 risk is rated Medium because Browser-Update.org operates a globally-used script delivery service embedded on ~229,716 websites. A security incident affecting the script delivery infrastructure (e.g., script injection, DNS hijacking, server compromise) could have cascading effects on all websites using the service and their end users. This creates a meaningful information security risk profile. However, the company is a micro-scale operation (2 named team members), making formal ISO 27001 certification practically and financially challenging. The absence of any documented ISMS increases the risk of an undetected security incident. The open-source code on GitHub provides some transparency but does not address operational security controls.

Evidence: https://browser-update.org/, https://github.com/browser-update/browser-update, https://www.iso.org/standard/27001

Financials

Three-year financials

Financial Resilience Score: 4/10

Browser-Update.org is operated as a German sole proprietorship (Einzelunternehmen) by Thomas Hümmer Webentwicklung, with no publicly disclosed financial statements. As such, no revenue, EBIT, or equity figures are available, and none are legally required under German HGB disclosure rules for sole proprietorships. This makes any objective financial resilience scoring inherently limited. On the positive side, the project has an extremely low cost base: it is a static JavaScript file delivered via CDN with effectively no employees, no payroll burden, and significant in-kind support (BrowserStack sponsorship, open-source community contributions via GitHub and Crowdin). The project has survived ~17 years since its founding in 2008, demonstrating operational durability and embedded reach across ~229,716 websites. However, significant structural risks weigh against resilience. The project is free-of-charge with unclear monetization (likely modest ad revenue only), depends entirely on 1-2 key individuals with no visible succession plan, and operates under unlimited personal liability as a sole proprietorship. Additionally, the underlying market need is in structural decline as modern browsers (Chrome, Edge, Firefox, Safari) auto-update, shrinking the addressable use case over time. No equity buffer is disclosed, so financial resilience effectively depends on the personal finances of the proprietor.

Key strengths: Negligible cost base — static JS file delivered via CDN, No salaried employees beyond the proprietor; no payroll burden, Embedded in ~229,716 websites providing organic distribution, Open-source community contributions reduce maintenance cost, In-kind sponsorship from BrowserStack for cross-browser testing, Long operating history since 2008 (~17 years) demonstrating durability, ~87 million cumulative visitors updated via the tool

Risk factors: Unclear and likely minimal monetization (no paid product), Key-person dependency on Thomas Hümmer and David Danier, No visible corporate continuity or succession plan, Structural decline in underlying need as browsers auto-update, Sole proprietorship structure means unlimited personal liability, No equity buffer disclosed; resilience depends on owner's personal finances, No financial transparency or public filings available

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report