Divi Pixel
Poland · www.divi-pixel.com · 15 vendors
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 5
- Financial Resilience: 6
Technology vendors
- Awesome Motive — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- WP Rocket — Technology — France
- and 12 more
Services catalogue
1 service in catalogue across 1 category; runs on 15 sub-vendors.
- Divi Pixel
Insights
Last updated 2026-08-01 · revision 2
15 direct vendors, 174 subvendors
Direct vendors by controlling owner country (sample)
- Switzerland: 1
- Denmark: 1
- France: 2
Subvendors by controlling owner country (sample)
- Canada: 5
- Poland: 1
- Spain: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Divi Pixel demonstrates low migration readiness. The primary challenge stems from extreme vendor lock-in with Elegant Themes; the 'Divi Pixel Plugin' is 'built exclusively for the Divi Theme' and utilizes the 'Divi Builder API'. Migrating away from this core dependency would necessitate a complete re-platforming and re-development of their flagship product, incurring substantial cost and effort. The 'Internal Tech Stack' is based on 'WordPress' and 'PHP', representing a traditional monolithic architecture that is not inherently cloud-native, containerized, or microservices-based, making a modern cloud migration a complex re-architecture project rather than a simple lift-and-shift. Furthermore, critical data gaps exist for 'Regulatory Environment' and 'Data Residency Requirements', introducing significant unknowns and potential compliance hurdles that could complicate and delay any migration efforts. The absence of data on financial stability (revenue concentration, growth history) also makes it impossible to assess the company's capacity to fund a potentially expensive and complex migration. While the use of common web technologies (PHP, JavaScript, CSS) means developer skills are available, this is overshadowed by the deep architectural and vendor dependencies.
Compliance
7 in-scope frameworks identified; showing 3.
ePrivacy Directive — Partially Compliant
ePrivacy risk is HIGH. The website uses Google Analytics (tracking cookies) and Facebook social sharing integrations, which require prior informed consent under the ePrivacy Directive as interpreted by GDPR. The privacy policy acknowledges 'Targeting Cookies' for Facebook sharing and 'Functional Cookies' for Google Analytics tracking, but no cookie consent management platform (CMP) with granular opt-in controls was observed on the website. The Court of Justice of the EU (CJEU) Planet49 ruling and subsequent EDPB guidelines make clear that pre-ticked boxes and implied consent are insufficient. Estonia's Andmekaitse Inspektsioon enforces ePrivacy rules. Non-compliant cookie practices are among the most commonly enforced GDPR/ePrivacy violations across EU member states.
Evidence: https://www.divi-pixel.com/privacy-policy/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058, https://www.aki.ee/en/personal-data/cookies
SOC 2 (source) — Assessment Required
SOC 2 risk is MEDIUM. While SOC 2 is a voluntary framework (not a legal mandate), it is increasingly expected by enterprise customers of SaaS and software providers. Divi Pixel sells a WordPress plugin on a subscription/license basis to a global customer base including businesses. Enterprise and mid-market customers increasingly require SOC 2 Type II reports from software vendors as part of their vendor due diligence. The absence of a SOC 2 report could limit Divi Pixel's ability to sell to larger enterprise customers or those in regulated industries. However, given that Divi Pixel appears to target individual web designers, freelancers, and small businesses (rather than large enterprises), the immediate commercial risk is moderate rather than high. The risk is not of regulatory penalty but of competitive disadvantage and customer trust.
Evidence: https://www.divi-pixel.com/privacy-policy/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
ISO 27001 (source) — Assessment Required
ISO 27001 risk is MEDIUM. As a software company processing customer personal data and payment information, Divi Pixel has information security obligations under GDPR (Art. 32 — appropriate technical and organisational security measures) that align with ISO 27001 principles. While ISO 27001 certification is voluntary, the absence of a formal ISMS (Information Security Management System) increases the risk of security incidents, which would trigger GDPR breach notification obligations (Art. 33/34). The company's use of third-party payment processors (PayPal, Stripe) mitigates some payment data security risk, but website security, customer account data, and license key management remain in scope. For a software plugin company, security vulnerabilities in the plugin itself could also affect thousands of customer websites, amplifying reputational and legal risk.
Evidence: https://www.divi-pixel.com/privacy-policy/, https://www.iso.org/standard/27001, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Divi Pixel, operated by Octolab OÜ, is a small niche WordPress plugin business with attractive economic characteristics but material concentration risks. The recurring subscription revenue model combined with lifetime license sales provides predictable cash flow, and the digital-only product with no inventory or physical distribution keeps operating costs low. Strong customer sentiment (5-star reviews on Trustpilot), a broad international customer base, and continued active product development (including the Divi 5 migration) support ongoing business viability. The Estonian OÜ structure adds a tax-efficiency advantage since retained earnings compound without corporate tax until distribution. However, the business carries significant structural risks that cap its resilience score. The entire product depends on a single third-party platform (Divi theme by Elegant Themes), meaning any strategic change by Elegant Themes could materially impair demand. The team appears very small with key-person concentration around the founder Maciej, and the WordPress plugin market is competitive with several direct rivals. Combined with limited financial transparency (small private OÜ with minimal public disclosure) and exposure to broader WordPress ecosystem risk versus modern site-builders like Webflow and Framer, the company sits in a moderately resilient position typical of a successful but small niche software vendor.
Key strengths: Recurring subscription revenue model with predictable cash flow, Low operating cost base as digital-only product with no inventory, Strong customer sentiment and 5-star reviews across markets, Broad international customer base across North America and Europe, Active product development including Divi 5 migration, Estonian OÜ tax structure allows tax-free compounding of retained earnings
Risk factors: Single-platform dependency on Divi theme by Elegant Themes, Key-person risk with concentrated technical knowledge in small team, Competitive niche market with direct rivals (Divi Supreme, Divi Essentials, Divi Flash, Divi Booster), Currency and payment-processor risk from global USD/EUR sales, Limited public financial transparency as small private OÜ, Long-term WordPress ecosystem risk vs. modern site-builders (Webflow, Framer, Wix), Effectively single-product revenue concentration (~100%)
Revenue by product/service
- Divi Pixel plugin licenses: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.