OxyMade

India · oxymade.com · 9 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 9 sub-vendors.

Insights

Last updated 2026-06-18 · revision 2

9 direct vendors, 127 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OxyMade demonstrates low migration readiness. The primary challenge stems from a very high degree of vendor lock-in to the Oxygen Page Builder. All of OxyMade's core products (OxyMade Framework, Layers, Premium Website Templates, Classic Blocks, OxyMade Design System) are built specifically for or around the Oxygen ecosystem. Migrating away from Oxygen would necessitate a complete re-platforming and redesign of their entire product line, representing a massive undertaking and cost. The underlying tech stack of WordPress and PHP is traditional and monolithic, not cloud-native, containerized, or microservices-based, which further complicates migration to modern cloud environments. Furthermore, critical information regarding regulatory environment, data residency requirements, and financial stability (which would dictate the ability to fund such a complex migration) is not available. While there is some geographic diversity among service vendors (United States, Germany), the deep integration with Oxygen Builder is the overwhelming factor limiting migration readiness.

Compliance

6 in-scope frameworks identified; showing 3.

PCI DSS (source) — Assessment Required

OxyMade processes credit card payments through its e-commerce platform (Easy Digital Downloads). PCI DSS applies to any entity that stores, processes, or transmits cardholder data. Risk is MEDIUM because: (1) if OxyMade uses a fully hosted payment gateway (e.g., Stripe, PayPal) that handles all card data without OxyMade's servers touching card numbers, PCI DSS scope may be limited to SAQ A; (2) however, if any card data flows through OxyMade's servers, full PCI DSS compliance is required; (3) no PCI DSS compliance documentation is publicly available; (4) payment card breaches carry significant financial penalties and reputational damage.

Evidence: https://oxymade.com/privacy/, https://oxymade.com/terms/

GDPR (source) — Partially Compliant

OxyMade explicitly acknowledges GDPR applicability in its privacy policy and serves EU/EEA customers globally through its SaaS/digital product platform. The company collects personal data (name, email, payment details, IP addresses, usage analytics) from EU/EEA residents. Risk is HIGH because: (1) the company is a small Indian entity with limited compliance infrastructure; (2) the privacy policy references GDPR but lacks key GDPR-required elements such as a named Data Protection Officer (DPO), explicit legal bases for each processing activity, detailed data subject rights procedures, and Standard Contractual Clauses (SCCs) for international data transfers; (3) data is transferred to the US without clear adequacy mechanism documentation; (4) the operating entity (BigFat Websites Private Limited) has a 'Strike Off' status with MCA, raising concerns about corporate governance; (5) GDPR fines can reach €20M or 4% of global annual turnover.

Evidence: https://oxymade.com/privacy/, https://www.zaubacorp.com/company/BIGFAT-WEBSITES-PRIVATE-LIMITED/U72200TG2018PTC124442

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognized standard for information security management applicable to any organization that handles sensitive data. OxyMade processes customer personal data, payment information, and account credentials. Risk is MEDIUM because: (1) no ISO 27001 certification has been found; (2) the company's privacy policy describes security measures at a high level without specifics; (3) as a small SaaS company serving global customers, lack of ISO 27001 certification may be a competitive disadvantage and indicates potential gaps in formal ISMS; (4) the operating entity's 'Strike Off' MCA status raises questions about organizational governance that could affect security management.

Evidence: https://oxymade.com/privacy/

Financials

Three-year financials

Financial Resilience Score: 4/10

OxyMade appears to be a small, privately operated Indian digital-products business with no public financial disclosure. The business model has inherent strengths: pure digital downloads with near-zero marginal cost yield very high gross margins, and lifetime deal pricing captures upfront cash, providing a strong working-capital profile. The site has been live since May 2021, indicating roughly 5 years of trading history, and shows active product development cadence (1 template/week, 10+ blocks/week), suggesting an operational going concern. However, significant risks weigh against resilience. The entire product line is tied to Oxygen Builder, a relatively niche WordPress page-builder with uncertain development direction—a decline would cripple demand. The Lifetime Deal model creates a long-tail support obligation against one-shot revenue. The business shows micro-team/key-person risk (likely solo founder 'anvesh'), no financial transparency, no disclosed legal entity, and faces competitive pressure from larger marketplaces like Envato/ThemeForest and Elementor template kits. Without verifiable financials, a moderate-to-low resilience score is appropriate.

Key strengths: Low-overhead digital-only business model with near-zero marginal cost, Lifetime Deal pricing captures upfront cash flow, Active product cadence: 1 template/week, 10+ blocks/week, Broad accumulated catalogue (68 templates, 605 modern blocks, 1,633 classic blocks, 736 pages), Established niche position claiming 5,000+ designers trusted, ~5 years of trading history since May 2021, USD revenue with likely INR cost base favorable for margins

Risk factors: Single-platform dependency on Oxygen Builder (niche WordPress page-builder), Lifetime Deal model creates long-tail support cost vs. front-loaded revenue mismatch, Micro-business/key-person risk (likely solo founder), No financial transparency, no audited accounts, no disclosed legal entity, FX exposure between USD revenue and INR costs, Competitive pressure from Envato/ThemeForest, Elementor, Bricks template marketplaces, Risk of Oxygen Builder discontinuation or decline

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report