Flywheel (WP Engine, Inc.)

United States · getflywheel.com · 17 vendors

Flywheel, an operating subsidiary of WP Engine, Inc., provides managed WordPress hosting and workflow tools. It enables designers and agencies to efficiently build, launch, and manage WordPress websites. The platform offers features such as nightly backups, robust security, fast performance, and collaboration tools.

Resilience scores

Disruption prediction

Flywheel (WP Engine, Inc.) has an estimated 27% probability of disruption in the next 6 months.

9 of Flywheel (WP Engine, Inc.)'s 17 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 17 sub-vendors.

Insights

Last updated 2026-08-14 · revision 7

17 direct vendors, 193 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Flywheel (WP Engine, Inc.) exhibits good migration readiness. The company's internal tech stack, built on Google Cloud Platform (GCP) and utilizing standard technologies like NGINX, Linux, WordPress, and PHP, provides a strong foundation for portability. The use of a major public cloud provider (GCP) inherently reduces the complexity of migrating from legacy on-premise infrastructure. Development workflows such as 'Local (Local by Flywheel)', 'Blueprints', and 'Staging Environments' facilitate testing and deployment, which are beneficial for managing migration processes. Financially, Flywheel's strong revenue growth and substantial estimated revenue indicate ample resources to fund a significant migration effort if required. However, several factors introduce complexity. The company's compliance with GDPR and California Privacy Laws (CCPA/CPRA) means any migration must carefully maintain these regulatory standards. Data residency requirements are managed through Standard Contractual Clauses (SCCs) and EU-US Data Privacy Framework certification for international transfers, and a migration would necessitate re-evaluating and establishing equivalent legal mechanisms in a new environment, especially given their global data processing model. The unknown status of SOC2 and ISO 27001 certifications could also complicate due diligence or compliance requirements with a new hosting provider or environment. While the 'Total Vendors: 0' is contradictory, the presence of 'Total Services: 22' from vendors across 6 unique countries suggests a diverse vendor landscape, which generally mitigates extreme vendor lock-in, though the specific 'Vendor Lock-in Risk' remains unknown.

Compliance

8 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 (Information Security Management System) is highly relevant for a managed hosting provider of Flywheel/WP Engine's scale and enterprise customer base. The company serves 1.5M+ customers across 150 countries including major enterprise brands, and operates critical digital infrastructure. ISO 27001 certification is increasingly expected by enterprise customers and is often required for EU public sector contracts. Risk is Medium because the company demonstrates strong security practices (encryption, 2FA, malware scanning, vulnerability disclosure program via Intigriti) that are consistent with ISO 27001 controls, but no public certification has been confirmed. The absence of a publicly listed ISO 27001 certificate is a transparency gap for enterprise procurement.

Evidence: https://getflywheel.com/security/, https://wpengine.com/legal/, https://app.intigriti.com/programs/wpengine/wpengine/detail

NIS2 (source) — Assessment Required

NIS2 Directive (EU) 2022/2555 includes 'digital infrastructure' and 'digital providers' (specifically cloud computing service providers and managed service providers) as covered entities. Flywheel/WP Engine is a managed cloud hosting provider serving customers across EU member states including Denmark, Finland, France, Ireland, and the Netherlands. As a managed hosting and cloud services provider with operations in the EU and a global customer base exceeding 1.5 million across 150 countries, WP Engine likely meets the size thresholds (50+ employees, €10M+ turnover) for NIS2 applicability as an Important Entity or potentially Essential Entity under the 'digital infrastructure' or 'ICT service management' categories. Risk is Medium because while the sector match is strong, formal NIS2 compliance status has not been publicly disclosed, and the specific EU entity structure and registration status under NIS2 national implementations is not confirmed from available public sources.

Evidence: https://wpengine.com/legal/dsa-transparency-report/, https://wpengine.com/legal/, https://getflywheel.com/security/, https://wpengine.com/legal/privacy/

SOC 2 (source) — Assessment Required

Flywheel/WP Engine is a cloud services and managed hosting provider — precisely the type of organization for which SOC 2 (Service Organization Control 2) was designed. Enterprise and agency customers routinely require SOC 2 Type II reports as part of vendor due diligence. The company serves 1.5M+ customers including major enterprise brands (Forbes, DirecTV, Lenovo, Washington Post referenced on Flywheel's security page), making SOC 2 compliance highly commercially relevant. Risk is Medium because while no public SOC 2 report has been found in Flywheel's public documentation, WP Engine as the parent company likely maintains SOC 2 compliance for enterprise sales purposes — but this cannot be confirmed from publicly available sources alone. The absence of a public SOC 2 attestation page is a gap in transparency.

Evidence: https://getflywheel.com/security/, https://wpengine.com/legal/, https://wpengine.com/legal/terms-of-service/

Financials

Three-year financials

Financial Resilience Score: 6/10

WP Engine (parent of Flywheel) operates a recurring subscription-based managed WordPress hosting model, which typically produces predictable cash flow and high gross retention. The company is backed by Silver Lake, which took a majority stake in January 2018 for approximately US$250M, providing significant capital and strategic support. WP Engine has grown from ~US$132M in 2017 revenue to an estimated ~US$400M range by 2023-2024 through organic growth and acquisitions (StudioPress, Flywheel, Delicious Brains/ACF). However, as a private, PE-owned company with no SEC filings, audited financials are not publicly available, limiting transparency. The company faces material near-term risk from its late-2024 public dispute with Automattic/Matt Mullenweg over WordPress.org access, which led to an October 2024 federal lawsuit. This creates reputational, operational, and litigation risk given WP Engine's deep dependency on the WordPress ecosystem. Additionally, competitive pressure from Kinsta, Pantheon, Cloudways, Pressable, SiteGround, and hyperscalers, combined with likely PE leverage, moderates the resilience score.

Key strengths: Recurring subscription revenue model with predictable cash flow, Silver Lake majority ownership since 2018 (~US$250M investment), Broad product portfolio: WP Engine, Flywheel, Local, StudioPress, ACF, Delicious Brains, 200,000+ customers across 150+ countries, Leading position in managed WordPress hosting niche, Growth from ~US$132M (2017) to estimated ~US$400M (2023-2024)

Risk factors: Ecosystem dependency on WordPress and WordPress.org, Active litigation vs. Automattic/Matt Mullenweg (filed Oct 2024), Competitive pressure from Kinsta, Pantheon, Cloudways, Pressable, SiteGround, hyperscalers, Likely PE-related leverage (terms undisclosed), FX and macro exposure from international operations, Single-technology (WordPress) concentration risk, No public audited financials — limited transparency

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report