Dream-Theme

Ukraine · the7.io · 16 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 16 sub-vendors.

Insights

Last updated 2026-08-16 · revision 7

16 direct vendors, 230 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Dream-Theme demonstrates medium-low migration readiness. The primary challenges stem from significant regulatory and data residency complexities. The explicit processing of personal data in Russia, coupled with high-risk GDPR non-compliance (outdated policy, insufficient transfer mechanisms for US, India, Australia, Ukraine, and Russia), necessitates a complete re-architecture of data flows and a robust legal strategy before any major migration. The company's headquarters in Ukraine also adds geopolitical risk and regulatory uncertainty under Ukrainian data protection law. The current tech stack, centered around WordPress and PHP, is traditional and not inherently cloud-native, containerized, or microservices-oriented, meaning a migration to a modern cloud environment would require substantial re-platforming efforts. Furthermore, Dream-Theme's reliance on Freemius for subscription and license management represents a critical vendor lock-in point for its core business logic; migrating away from this platform would be a complex and resource-intensive undertaking. The 100% revenue concentration on a single product means any disruption during a migration could have severe financial consequences. Additionally, the recent rollout of direct sales licensing in 2025 suggests ongoing internal resource allocation to platform transitions, potentially limiting capacity for another large-scale infrastructure migration. The lack of public SOC2 or ISO 27001 certifications also means that demonstrating security compliance post-migration would be more challenging. Opportunities for migration include the existing distributed web hosting infrastructure, which indicates some experience with multi-region deployments, and the company's active product development (e.g., FSE support), suggesting a capacity for technological evolution.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

Dream-Theme handles personal data of 300,000+ customers globally, operates a support portal where sensitive credentials are shared, and stores data across multiple jurisdictions. ISO 27001 certification would be appropriate for a company of this profile. However, no certification has been found publicly. The risk is MEDIUM because: (1) the company's data handling practices (collecting FTP/admin credentials in support tickets) represent meaningful information security risk; (2) no independent security certification is publicly available; (3) the privacy policy references security measures but without independent verification; (4) the company is based in Ukraine, which has experienced significant cybersecurity threats in recent years, increasing the relevance of formal ISMS frameworks.

Evidence: https://the7.io/privacy-policy/, https://dream-theme.com/

Ukrainian Personal Data Protection Law — Assessment Required

Dream-Theme is headquartered in Ukraine and is subject to Ukraine's Law on Personal Data Protection (Law No. 2297-VI, as amended). This law governs the collection, processing, storage, and transfer of personal data by Ukrainian entities. The company processes personal data of 300,000+ customers globally. Key requirements include: registration of personal data databases with the Ukrainian Commissioner for Human Rights (Ombudsman), appointment of a responsible person for personal data protection, obtaining consent for data processing, and ensuring data subject rights. The risk is HIGH because: (1) the company is definitively subject to this law as a Ukrainian entity; (2) no evidence of compliance measures specific to Ukrainian law has been found; (3) the ongoing conflict in Ukraine creates additional operational and regulatory uncertainty.

Evidence: https://the7.io/privacy-policy/, https://dream-theme.com/

SOC 2 (source) — Assessment Required

Dream-Theme provides a SaaS-adjacent service model: customers purchase licenses, receive theme updates, and access a support portal (support.dream-theme.com). The company stores customer personal data (email addresses, purchase codes, IP addresses, support ticket content including potentially sensitive website credentials) on servers managed by them and third-party providers. While Dream-Theme is primarily a digital product vendor rather than a traditional cloud service provider, the nature of their support portal — where customers share WordPress admin credentials and FTP access — creates meaningful data security obligations. The risk is MEDIUM because: (1) the company handles sensitive customer credentials in support workflows; (2) no SOC2 certification or equivalent security attestation is publicly available; (3) the company's privacy policy references security controls but provides no independent verification. SOC2 is not legally mandated but is increasingly expected by enterprise customers.

Evidence: https://the7.io/privacy-policy/, https://the7.io/terms-of-service/, https://support.dream-theme.com/

Financials

Three-year financials

Financial Resilience Score: 6/10

Dream-Theme is a small, founder-led, bootstrapped Ukrainian WordPress theme studio with no audited or publicly filed financial statements. Public marketplace data indicates it is a ThemeForest 'Power Elite Author' (>$1M lifetime Envato earnings) with roughly 337,000 cumulative sales of its flagship The7 theme, implying an estimated lifetime GMV of approximately $15M and a recent-year run rate in the low-to-mid single-digit US$ millions. The business enjoys a very lean cost structure (approximately 8-15 employees, distributed/remote), strong customer ratings (4.65/5 across ~13,200 ThemeForest ratings), and a proven, long-lived product active since 2013. Resilience is enhanced by an ongoing strategic pivot from one-time ThemeForest licenses to direct annual subscriptions via Freemius ($49/yr and $249/yr renewal tiers), which introduces recurring revenue. However, the company faces meaningful risks including heavy channel concentration on Envato/ThemeForest, near-total product concentration in The7 (>95% of revenue), category-level decline in the premium WordPress theme market as Elementor, Divi, and SaaS builders take share, and Ukraine-specific operating risks including war, mobilization, infrastructure, and payment friction. Growth has slowed materially from ~30K sales/yr (2013-2022) to ~12-13K/yr (2022-2026).

Key strengths: Power Elite ThemeForest author status (>$1M lifetime Envato earnings), ~337,000 cumulative sales of The7 flagship theme, High customer satisfaction (4.65/5 across ~13,200 ratings), Very lean cost base with ~8-15 distributed employees, Long-lived product active since 2013, Strategic pivot to recurring annual subscriptions via Freemius, Diversified global customer geography, Bootstrapped with no external capital dependencies

Risk factors: Heavy channel concentration on Envato/ThemeForest marketplace, Single-product concentration (The7 = >95% of revenue), Structural decline of premium WordPress theme category since ~2018-2020, Ukraine country risk: war, mobilization, infrastructure outages, payment friction, Key-person risk from very small founder-led team, No visible outside capital; resilience depends on internal cash flow, Slowing growth: from ~30K sales/yr to ~12-13K/yr recently, Competition from Elementor, Divi, Squarespace, Webflow, Wix, Shopify

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report