Open Source Matters, Inc.
United States · www.joomla.org · 25 vendors
Open Source Matters, Inc. is a not-for-profit organization incorporated in the United States. It provides organizational, legal, and financial support for the Joomla! open-source project, a widely used content management system (CMS).
Resilience scores
- Digital Sovereignty: 76
- Digital Resilience: 5
Technology vendors
- jQuery Foundation — Technology — United States
- Netlify, Inc. — Technology — United States
- Open Source Matters, Inc. — Technology — United States
- and 23 more
Services catalogue
4 services in catalogue across 4 categories; runs on 25 sub-vendors.
- Joomla! CMS
- Website builder
- Enterprise DNS
Insights
Last updated 2026-03-13 · revision 1
25 direct vendors, 261 subvendors
Direct vendors by controlling owner country (sample)
- Estonia: 1
- United Kingdom: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- Italy: 2
- Norway: 3
- Germany: 7
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Open Source Matters, Inc. demonstrates medium migration readiness. The primary challenge lies in its traditional internal tech stack, which predominantly features PHP, MySQL/MariaDB/PostgreSQL, and Apache HTTP Server. While these technologies are robust, the absence of explicit mentions of cloud-native architectures, containerization (e.g., Docker, Kubernetes), or widespread microservices adoption suggests a potentially monolithic structure for its core products, which can complicate and prolong migration efforts. Significant unknowns also impact readiness: there is no data on financial stability, which is crucial for funding a large-scale migration, nor on specific regulatory environments or data residency requirements that could impose complex constraints. The 'Vendor Lock-in Risk' is also unknown, though the mention of Rochen as a web hosting provider for core infrastructure suggests a potential for lock-in with a key vendor. On the positive side, the modular nature of the Joomla! Framework could facilitate breaking down parts of their system for migration. The use of modern development tools like Git/GitHub and Composer, along with the implementation of RESTful Web Services/JSON API, indicates a foundation that can adapt to modern cloud environments. The open-source nature of its products also offers flexibility in choosing new platforms and providers, potentially reducing proprietary lock-in at the application level. The geographic diversity of its service vendors (8 countries) could also imply a less rigid vendor ecosystem, though the direct vendor lock-in risk remains unclear.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
Open Source Matters, Inc. processes personal data of EU/EEA residents through their global Joomla websites and services. While they have implemented privacy policies and data processing procedures, the complexity of managing multiple websites and international user base creates moderate compliance risk. The organization appears to have basic GDPR compliance measures in place but lacks evidence of comprehensive audit or certification.
Evidence: https://www.joomla.org/privacy-policy.html
SOC 2 (source) — Assessment Required
As a provider of cloud-based services (Joomla hosting, user accounts, data processing), OSM could benefit from SOC2 compliance to demonstrate security controls to users and partners. The risk is moderate because while not legally required, SOC2 certification would enhance trust and security posture for their global user base.
Evidence: https://www.joomla.org/privacy-policy.html
ISO 27001 (source) — Assessment Required
Given OSM's role in managing security for a widely-used CMS platform and handling personal data globally, ISO 27001 certification would demonstrate robust information security management. The risk is moderate as security incidents could significantly impact their reputation and the broader Joomla ecosystem.
Evidence: https://developer.joomla.org/security.html
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.