Muffin Group
Poland · muffingroup.com · 4 vendors
MUFFIN GROUP LTD is an experienced team that creates unique and easy-to-set-up themes for WordPress, as well as websites and web applications. They are known for their "Betheme" WordPress theme, which is a popular website builder for WordPress and WooCommerce.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 5
- Financial Resilience: 6
Technology vendors
- Google LLC — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- WordPress — Technology — United States
- and 1 more
Services catalogue
2 services in catalogue across 2 categories; runs on 4 sub-vendors.
- BeTheme
- WordPress Theme
Insights
Last updated 2026-04-22 · revision 2
4 direct vendors, 85 subvendors
Direct vendors by controlling owner country (sample)
- United States: 3
- Denmark: 1
Subvendors by controlling owner country (sample)
- Italy: 1
- France: 1
- Australia: 2
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Muffin Group demonstrates low to medium migration readiness. The primary challenge stems from its traditional monolithic WordPress-based architecture, which powers all products and support sites. This setup is not inherently cloud-native, containerized, or microservices-oriented, implying that a significant re-architecture effort would be required for a modern cloud migration. The dependency on PHP further reinforces this traditional approach. A critical external dependency is the Envato Market API for license management and purchase validation, which suggests a potential vendor lock-in with Envato for their flagship product, Betheme. Migrating away from this core distribution and licensing platform would be complex. Financial stability, crucial for funding a migration, is unknown due to missing revenue and growth data. On the positive side, there are no specified data residency requirements, which removes a common hurdle for cloud migrations. The company also has a moderate number of external services (5) from a few vendors, which is manageable. While the products include built-in GDPR compliance, the overall regulatory environment for the company is not specified, leaving some uncertainty regarding compliance requirements during a migration.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
As a Polish company (EU member state) that processes personal data from customers, employees, and website visitors, GDPR compliance is mandatory. Non-compliance can result in fines up to €20 million or 4% of annual turnover. The company shows awareness of GDPR through their cookie consent implementation and privacy documentation, but full compliance status requires detailed assessment of data processing activities, privacy policies, and technical/organizational measures.
Evidence: https://support.muffingroup.com/documentation/gdpr-cookies/, https://muffingroup.com
SOC 2 (source) — Assessment Required
While SOC2 is not mandatory, it's increasingly expected for software companies serving business customers, especially those handling customer data. As Muffin Group provides digital products and services to customers worldwide, SOC2 compliance could enhance customer trust and competitive positioning. The risk is moderate as lack of SOC2 may limit business opportunities with enterprise customers but won't result in regulatory penalties.
ISO 27001 (source) — Assessment Required
ISO 27001 is not mandatory but represents best practice for information security management. For a software company handling customer data and intellectual property, implementing ISO 27001 controls reduces security risks and enhances customer confidence. The risk level is moderate as poor security practices could lead to data breaches, customer loss, and reputational damage, though no direct regulatory penalties apply.
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Muffin Group demonstrates a structurally high-margin business model typical of digital product companies: near-zero marginal cost of distribution, a globally distributed customer base of 300,000+ users, and an exceptionally lean fixed-cost base of only 7 employees. The company has sustained operations for approximately 15 years without any reported external financing, strongly suggesting consistent profitability and positive cash generation consistent with a bootstrapped, self-funding model. The 700+ pre-built templates and large installed user base create meaningful switching costs and a durable competitive moat within its niche. However, the business carries significant concentration risk on multiple dimensions simultaneously. Virtually all revenue is estimated to derive from a single product (Betheme) sold through a single third-party marketplace (Envato/ThemeForest), which controls pricing visibility, search ranking, and takes a substantial revenue share commission. Any adverse change to Envato's terms, algorithm, or market position would have an immediate and outsized impact on Muffin Group's revenue. The long-term structural environment for traditional WordPress themes is deteriorating as page builders (Elementor, Divi, Bricks), full-site editing via Gutenberg, and alternative CMS platforms (Webflow, Framer) erode the addressable market. The company's 7-person team, while cost-efficient, creates acute key-person risk and limits capacity to diversify into new product lines or respond rapidly to competitive threats. Financial transparency is entirely absent — no statutory accounts, revenue, EBIT, or equity figures are publicly available — making independent verification of financial health impossible. The score of 6 reflects a genuinely resilient niche business model offset by severe platform dependency, single-product concentration, structural market headwinds, and complete financial opacity.
Key strengths: Dominant niche market position — Betheme is one of ThemeForest's best-selling multipurpose WordPress themes, Extremely lean cost structure with only 7 employees over 15 years of operation, 300,000+ installed user base providing recurring support revenue and word-of-mouth growth, 700+ pre-built website templates raising switching costs for existing users, No evidence of external debt or financing obligations — bootstrapped model implies self-funding profitability, 100% in-house software development reducing third-party licensing costs, Digital product model with near-zero marginal cost of distribution, Secondary affiliate revenue stream from promoted premium plugins (Slider Revolution, LayerSlider, WPML, HubSpot, Rank Math)
Risk factors: Single-product concentration — virtually all revenue estimated to derive from Betheme alone, Platform dependency on Envato/ThemeForest for distribution, pricing visibility, and search ranking, Envato commission structure takes a significant revenue share (historically up to 50% for non-exclusive authors), WordPress ecosystem risk from rise of competing website builders (Webflow, Squarespace, Wix, Framer), Gutenberg/Full Site Editing evolution within WordPress may erode traditional theme market, Key-person risk from 7-person team with limited capacity to diversify or respond to competitive threats, No geographic or product revenue diversification beyond WordPress themes, Currency risk — revenue denominated in USD (ThemeForest) while costs incurred in PLN, Commoditisation pressure from free themes and page builders competing directly, Complete financial opacity — no public accounts available to verify financial health
Revenue by geography
- United States: 40%
- Europe (ex-Poland): 35%
- Rest of World: 22%
- Poland (domestic): 3%
Revenue by product/service
- Betheme WordPress theme licences: 92%
- Premium plugin affiliate commissions: 5%
- Web development and custom projects: 3%
Workforce by country
- Poland: 7
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.