Joomlack

France · www.joomlack.fr · 4 vendors

Cédric KEIFLIN, operating as Joomlack, develops and provides extensions, modules, plugins, and components for the Joomla! content management system. The company also offers tutorials and a template creator to assist users in building and customizing Joomla! websites.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 4 sub-vendors.

Insights

Last updated 2026-07-01 · revision 1

4 direct vendors, 87 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Joomlack demonstrates low migration readiness. The primary challenge stems from its deeply embedded and traditional tech stack, relying heavily on Joomla! CMS, PHP, and MySQL. There is no indication of cloud-native architectures, containerization (e.g., Docker, Kubernetes), or microservices, suggesting a monolithic or tightly coupled structure that would require significant re-platforming or re-architecting rather than a simple lift-and-shift for a cloud migration. The company's core products are extensions and templates for Joomla! and WordPress, indicating a high degree of platform lock-in. Financial stability, crucial for funding a major migration, is unknown due to a lack of revenue and growth data. While data residency requirements are not specified, operating from France likely subjects them to GDPR, which could introduce compliance complexities during migration. Vendor lock-in risk is unknown for the 4 external services, but the fundamental reliance on the Joomla! ecosystem represents a substantial lock-in for their business model. The absence of modern cloud practices and the deep integration with a traditional CMS platform are the main drivers for the low readiness score.

Compliance

5 in-scope frameworks identified; showing 3.

French LCEN — Partially Compliant

The LCEN (French Digital Economy Trust Act) requires all French commercial websites to publish mandatory legal notices (mentions légales) including: operator identity, SIRET number, VAT number, registered address, hosting provider details, and editorial director. Joomlack's mentions légales page includes the operator name (Cédric KEIFLIN), SIRET (510 904 410 00030), VAT number (FR 43 510904410), address (6 rue de Pommeret, 68370 Orbey), and hosting provider (PlanetHoster). This is broadly compliant with LCEN Article 6. However, the page was last updated in 2017 and may not reflect current requirements. The risk is Medium because partial compliance is evident but the page lacks some detail (e.g., no phone number, no publication director explicitly named beyond the author). French DGCCRF (consumer protection authority) can investigate and sanction non-compliant e-commerce operators.

Evidence: https://www.joomlack.fr/mentions-legales, https://www.joomlack.fr/conditions-generales-de-vente, https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000801164

French ePrivacy — Partially Compliant

France's implementation of the ePrivacy Directive (via CNIL guidelines updated in 2020/2021) requires websites to obtain prior, informed, and freely given consent before placing non-essential cookies (including analytics cookies like Google Analytics). Joomlack has a cookie consent banner that offers 'Accept All' and 'Decline All' options, with a specific toggle for Google Analytics. This is a positive compliance signal. However, the risk is Medium because: (1) it is unclear whether cookies are blocked prior to consent (technical implementation cannot be verified from page source alone); (2) the cookie banner does not appear to offer granular consent categories beyond analytics; (3) no cookie policy page with full disclosure of all cookies used is linked from the banner; (4) CNIL has been actively enforcing cookie consent rules and has fined numerous French companies. The presence of a consent mechanism is a significant positive, but full technical compliance cannot be confirmed without a deeper audit.

Evidence: https://www.joomlack.fr, https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/que-dit-la-loi, https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies/lignes-directrices-modificatives-et-recommandation

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognised information security management standard. While it is voluntary (not legally mandated), it is highly relevant for any technology company that collects, stores, and processes customer personal data and payment transaction records. Joomlack collects user account data, purchase history, and payment information (via PayPal) from a global customer base. As a sole trader, formal ISO 27001 certification is uncommon and likely disproportionate to the company's size and resources. However, the underlying security principles (access controls, data protection, incident response) are directly relevant to GDPR compliance obligations (Article 32 — security of processing). The risk is Medium because: (1) the company processes personal and financial data of customers; (2) no evidence of any information security framework or controls is publicly documented; (3) a security incident could trigger GDPR breach notification obligations; (4) the website uses Google Analytics and PayPal integrations which introduce third-party security dependencies. The absence of any documented security posture is a gap, even if formal ISO 27001 certification is not expected for a micro-enterprise.

Evidence: https://www.joomlack.fr, https://www.iso.org/standard/27001, https://www.planethoster.net/

Financials

Three-year financials

Financial Resilience Score: 6/10

Joomlack is a long-standing French individual entrepreneurship (entreprise individuelle) operated by Cédric KEIFLIN since 2010, publishing Joomla! CMS extensions and tutorials. The business has demonstrated 15+ years of continuous operation, suggesting it is cash-flow-positive and sustainable at its current scale. Its digital product model with subscription-based offerings (notably the 'Pack Tout en 1' bundle) provides recurring revenue with minimal fixed costs and no employee overhead. However, financial resilience is constrained by several structural factors. As a French EI, likely under the micro-entrepreneur regime, revenue is legally capped (approximately €77,700/year for services). The business faces significant key-person risk being entirely dependent on a single founder, and platform concentration risk since 100% of revenue is tied to Joomla!, a CMS with declining market share (under 3% of CMS-based websites). No public financial statements are available since EIs are not required to file annual accounts in France, making external verification of solvency impossible. Overall, the business appears operationally resilient at its niche scale but lacks the diversification, corporate structure, and financial transparency that would justify a higher resilience score.

Key strengths: 15+ years of continuous operation since 2010, Recurring subscription revenue via 'Pack Tout en 1' bundle, Very low fixed-cost structure with no employees, Diversified product catalogue of 20+ extensions plus e-books, Well-known brand in the Joomla niche (Maximenu CK, Slideshow CK, etc.), International digital distribution reach

Risk factors: Key-person risk: entire business depends on single founder Cédric KEIFLIN, Platform concentration: 100% revenue tied to declining Joomla! CMS (<3% CMS market share), Competition from free/open-source alternatives and paid Joomla vendors (JoomShaper, YOOtheme, RSJoomla), No published accounts limits financial transparency and verification, Micro-entrepreneur regime imposes legal turnover cap (~€77,700/year for services), Historical unlimited personal liability under pre-2022 EI structure

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report