JS.ORG
Germany · js.org · 12 vendors
Resilience scores
- Digital Sovereignty: 50
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Algolia — Technology — United States
- ImprovMX — Technology — France
- Netlify, Inc. — Technology — United States
- and 10 more
Services catalogue
1 service in catalogue across 1 category; runs on 12 sub-vendors.
- Subdomain
Insights
Last updated 2026-08-04 · revision 2
12 direct vendors, 132 subvendors
Direct vendors by controlling owner country (sample)
- Austria: 1
- United States: 6
- Ireland: 1
Subvendors by controlling owner country (sample)
- Netherlands: 1
- Poland: 1
- United States: 101
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
JS.ORG demonstrates high migration readiness, scoring 75 out of 100. The tech stack, centered around GitHub Pages and Cloudflare, is inherently modern and conducive to migration. GitHub Pages provides static site hosting, which is generally straightforward to migrate to other cloud-native or serverless platforms. The use of JavaScript as a key technology also aligns with modern development practices. There are no indications of legacy systems, monolithic architectures, or complex databases that would hinder migration. However, the lack of financial data means the ability to fund a migration is an unknown. While the 'Vendor Lock-in Risk' is also unknown, the reliance on GitHub Pages for the core subdomain service could present a platform-specific lock-in, though static content itself is highly portable. The moderate number of vendors (estimated 5) and their geographic diversity are favorable, as they do not suggest overly complex vendor relationships that would impede migration.
Compliance
4 in-scope frameworks identified; showing 3.
TTDSG — Partially Compliant
The TTDSG (in force since December 2021) implements the EU ePrivacy Directive in Germany and governs the use of cookies and tracking technologies on websites. JS.ORG uses trackers and third-party advertising (Carbon Ads with behavioural retargeting) and explicitly states it does not support 'Do Not Track' requests. Under TTDSG §25, storing or accessing information on a user's terminal device (e.g., cookies, trackers) requires prior informed consent unless strictly necessary. The absence of a visible cookie consent mechanism or Consent Management Platform (CMP) on the JS.ORG website is a compliance gap. Risk is Medium because German data protection authorities (including LDA Bayern, the competent authority for JS.ORG) have been active in enforcing cookie consent requirements.
Evidence: https://js.org/privacy.html, https://www.gesetze-im-internet.de/ttdsg/, https://www.lda.bayern.de
GDPR (source) — Partially Compliant
JS.ORG is operated by an individual (Stefan Keim) based in Schwabhausen/Weil, Bavaria, Germany — squarely within the EU. The organisation collects personal data (Usage Data, IP addresses, trackers) from a global user base and explicitly references GDPR (Art. 13/14 of Regulation (EU) 2016/679) in its privacy policy. A published privacy policy exists and enumerates legal bases, data subject rights, and retention principles, which are positive indicators. However, several compliance gaps are evident: (1) The privacy policy was last updated December 12, 2021 — over three years ago — and may not reflect current processing activities or the latest regulatory guidance. (2) No Data Protection Officer (DPO) is identified; while a supervisory authority (Bayerisches Landesamt für Datenschutzaufsicht – LDA Bayern) is listed, there is no named DPO or formal DPO appointment disclosed. (3) The site states it does not support 'Do Not Track' requests, which raises questions about consent management. (4) Third-party data processors (Cloudflare, GitHub Pages, Carbon Ads/BuySellAds, Namecheap) transfer personal data to the United States; the policy references these transfers but does not specify the transfer mechanism (e.g., Standard Contractual Clauses, adequacy decision) used to legitimise them post-Schrems II. (5) No cookie consent banner or Consent Management Platform (CMP) is evidenced on the site. These gaps elevate risk from Low to Medium despite the small scale of the operation.
Evidence: https://js.org/privacy.html, https://js.org/imprint.html, https://www.lda.bayern.de, https://gdpr-info.eu/art-13-gdpr/, https://gdpr-info.eu/art-14-gdpr/
TMG — Compliant
The TMG (and its successor provisions under the Digital Services Act implementation) requires German website operators to publish a legally compliant imprint (Impressum) with full contact details. JS.ORG publishes a detailed imprint at js.org/imprint.html including the operator's full name, postal address, email, phone number, and the competent supervisory authority. This satisfies the §5 TMG imprint obligation. Risk is Low as the imprint appears complete and compliant.
Evidence: https://js.org/imprint.html, https://www.gesetze-im-internet.de/tmg/__5.html
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 4/10
JS.ORG is not a commercial entity but a personal community project run by a single individual (Stefan Keim) in Bavaria, Germany. It has no revenue, no employees, no corporate structure, and no filed financial statements. Its entire financial footprint consists of approximately $88/year in voluntary micro-donations collected through Open Collective, used solely to cover the .org domain registrar fee. The current cash balance of ~$265 represents roughly 3x the annual budget, providing a modest cushion. From a pure cost-coverage perspective, the project is financially sustainable because its cost base is trivially small and hosting is offloaded to GitHub Pages at no cost. However, resilience is fundamentally constrained by its non-corporate nature. There is significant key-person risk: the entire service depends on one individual who is personally liable under German law with no legal entity providing a liability shield. Donation-dependency and platform-dependency (GitHub Pages) add further fragility. The score reflects that while the project is unlikely to fail financially given its microscopic budget, it lacks any of the structural resilience features (diversified revenue, legal entity, succession planning, reserves at scale) that would warrant a higher rating.
Key strengths: Extremely low cost base (only annual .org domain fee), Hosting offloaded to GitHub Pages at no cost, Cash reserve (~$265) covers ~3x annual budget, No debt, no employees, no material liabilities, Strong community goodwill with 3,000+ projects using service, Open Collective provides transparent fiscal hosting
Risk factors: Key-person risk: single individual operator with no succession plan, No legal entity — personal liability under German law for owner, GDPR and content-liability exposure across 3,000+ subdomains, 100% donation-dependent funding model, Platform dependency on GitHub Pages remaining free, Not a going concern in the corporate sense — hobby project, High donor concentration (top 2 contributors ~40% of all-time raised)
Revenue by geography
- Global (individual contributors worldwide): 100%
Revenue by product/service
- JavaScript project subdomains (js.org): 100%
Workforce by country
- Germany: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.