Never5

Netherlands · www.download-monitor.com · 8 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 8 sub-vendors.

Insights

Last updated 2026-08-17 · revision 1

8 direct vendors, 136 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Never5's migration readiness is assessed at 50, indicating a medium level of readiness with notable challenges and opportunities. A primary challenge stems from the core application stack (WordPress, PHP, MySQL), which is not cloud-native, containerized, or microservices-based. A migration to a modern cloud-native architecture would likely necessitate significant re-platforming or refactoring efforts, increasing complexity, time, and cost. A major impediment to assessing readiness is the lack of data on financial stability (revenue concentration, growth history), making it impossible to determine the company's capacity to fund a potentially large-scale migration project. Similarly, the regulatory environment and data residency requirements are 'Not specified', which could introduce unforeseen compliance challenges and costs during migration planning and execution. The 'Vendor Lock-in Risk: Unknown' for its 9 vendor services also means the complexity of disentangling dependencies and contracts is unclear. On the positive side, Never5 has existing experience with major cloud providers (Amazon S3, Google Cloud) and Cloudflare, indicating familiarity with cloud environments and APIs, which provides a foundational advantage. The use of REST API / WordPress Hooks & Shortcodes suggests some level of modularity in the application, which could aid in breaking down components for a phased migration strategy. The geographic diversity of vendor HQ/owner countries (3 unique countries) also suggests a potentially lower risk of being tied to a single geopolitical region for critical services.

Compliance

7 in-scope frameworks identified; showing 3.

Romanian Data Protection Law — Assessment Required

Romania transposed GDPR through Law No. 190/2018, which supplements GDPR with national-specific provisions including specific rules on employee data processing, processing for journalistic/research purposes, and national security exceptions. As a Romanian-incorporated company, Chill Media Labs S.R.L. is subject to both GDPR and Romanian national data protection law. The ANSPDCP (Romanian DPA) is the supervisory authority. The same compliance gaps identified under GDPR apply here, with additional risk from Romanian-specific provisions. Risk is High for the same reasons as GDPR.

Evidence: https://download-monitor.com/privacy-policy/, https://www.dataprotection.ro/?page=formulare&lang=ro, https://legislatie.just.ro/Public/DetaliiDocument/202433

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA for service organizations that store, process, or transmit customer data in the cloud. Download Monitor operates a SaaS-adjacent model where it collects customer account data, payment information, and download analytics for 120,000+ businesses. Many enterprise customers and B2B buyers increasingly require SOC 2 reports from their software vendors as part of vendor due diligence. The absence of a SOC 2 report could be a commercial risk and a trust gap, particularly for enterprise customers. Risk is Medium because while SOC 2 is voluntary, the lack of a report may hinder enterprise sales and signals potential gaps in formal security controls documentation.

Evidence: https://download-monitor.com/privacy-policy/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

ePrivacy Directive — Non-Compliant

The ePrivacy Directive (implemented in Romania via Law No. 506/2004 as amended) requires prior informed consent before placing non-essential cookies on users' devices. Download Monitor's website uses persistent cookies, session cookies, affiliate tracking cookies (ShareASale), and third-party advertiser cookies. The privacy policy acknowledges these cookies but does not describe a cookie consent management platform (CMP) or prior consent mechanism. Users are told they can configure their browser to decline cookies, but this does not satisfy the ePrivacy requirement for prior, informed, specific consent. Risk is Medium because cookie law enforcement has been increasing across the EU, and the Romanian DPA (ANSPDCP) has issued guidance on cookie compliance.

Evidence: https://download-monitor.com/privacy-policy/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058, https://www.dataprotection.ro/

Financials

Financial Resilience Score: 4/10

Never5 B.V., the Dutch entity historically associated with the Download Monitor WordPress plugin, appears to be effectively dormant with respect to this product line. The Download Monitor business was transferred to Chill Media Labs S.R.L., a Romanian entity, around 2020. As a private micro-entity in either jurisdiction, no revenue, EBIT, or equity figures are publicly disclosed for the last three fiscal years. Dutch micro/small B.V.s file only limited balance-sheet information with KVK, and no P&L is published. The underlying business model has favorable characteristics: recurring annual subscription revenue with auto-renewal, low COGS typical of WordPress plugin businesses, and a large free-plugin footprint (120,000+ businesses cited in marketing) providing top-of-funnel conversion opportunities. The current owner (WPChill/Chill Media Labs) benefits from a portfolio effect across multiple WordPress plugins, diversifying product risk versus Never5's historic single-product setup. However, significant risks constrain resilience: 100% platform dependency on WordPress, very small team with key-person risk, freemium competition capping pricing power, ownership discontinuity (WooThemes → Never5 → WPChill), and minimal financial transparency. Inferred revenue is likely low-single-digit to mid-single-digit million EUR at most, though this is speculative. The score reflects a viable but small, opaque, single-platform business with meaningful concentration risk.

Key strengths: Established product with 120,000+ businesses adopting the plugin (cumulative), Recurring annual subscription revenue model with auto-renewal, Low fixed-cost software business with minimal COGS, Portfolio effect under current WPChill/Chill Media Labs ownership across multiple WordPress plugins, Long product history dating back to original development by WooCommerce creator Mike Jolley

Risk factors: 100% platform concentration on WordPress ecosystem, Very small team with key-person risk (estimated under 20 employees), Freemium competition from WP Download Manager, Simple Download Monitor, Easy Digital Downloads limiting pricing power, Ownership discontinuity across three transitions creating support-continuity concerns, Minimal financial disclosure as private micro-entity in both Dutch and Romanian jurisdictions, Never5 B.V. effectively dormant with respect to Download Monitor business

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report