OxyNinja

Czech Republic · oxyninja.com · 11 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-06-18 · revision 1

11 direct vendors, 144 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OxyNinja's current tech stack, heavily reliant on WordPress, WooCommerce, and PHP, is not inherently cloud-native, containerized, or microservices-based. A migration to a truly modern, scalable cloud architecture would likely necessitate significant re-platforming and development effort. The proprietary "Core Framework" could introduce complexities and potential lock-in during a migration. There is a critical lack of data regarding financial stability, making it impossible to assess the company's ability to fund a potentially costly migration. Similarly, the absence of information on regulatory environments and data residency requirements introduces unknown complexities and potential compliance hurdles. While "Total Vendors: 0" is stated, the deep integration with platforms like WordPress and Oxygen Builder represents a form of platform lock-in, which can complicate efforts to move to alternative systems or architectures. The broad ecosystem around WordPress and WooCommerce does offer numerous tools and services for migration, often to managed environments, but a full re-architecture would be challenging.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR is mandatory for all EU/EEA-based companies processing personal data. OxyNinja is headquartered in the Czech Republic (EU member state) and demonstrably collects personal data including: customer account credentials (username/email), payment information for digital product purchases, and behavioral tracking data via Facebook Pixel (Meta Pixel ID 2489590804670625 observed in page source). Non-compliance risk is HIGH because: (1) no publicly accessible privacy policy was found on the website during research, (2) Facebook Pixel is actively deployed without a visible cookie consent mechanism confirmed, (3) fines can reach €20M or 4% of global annual turnover, (4) Czech DPA (ÚOOÚ) actively enforces GDPR, and (5) the company sells to an international customer base including EU residents. The absence of a visible privacy policy and cookie consent banner are significant red flags.

Evidence: https://oxyninja.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679, https://www.uoou.cz/en/

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework but is increasingly expected by enterprise customers of cloud/SaaS providers. OxyNinja provides digital software products (plugins, design sets, templates) delivered via a web platform with customer accounts and payment processing. While SOC 2 is not legally mandated, the absence of a SOC 2 report may be a commercial risk if OxyNinja targets professional web agencies or enterprise clients who require vendor security assurances. Risk is MEDIUM because: (1) the company processes customer account data and payment information, (2) enterprise/agency customers may require SOC 2 as a procurement condition, (3) no SOC 2 report is publicly available. However, as a small/micro company primarily serving individual freelancers and small agencies, the immediate commercial pressure for SOC 2 may be limited.

Evidence: https://oxyninja.com, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

Czech Consumer Protection — Assessment Required

EU Directive 2019/770 on contracts for the supply of digital content and digital services (transposed into Czech law) applies to companies selling digital products to consumers. OxyNinja sells digital products (plugins, design sets, templates) directly to end users including individual freelancers (consumers). Requirements include conformity guarantees, remedies for non-conformity, and specific terms for digital content contracts. Risk is MEDIUM because: (1) OxyNinja sells digital products to consumers, (2) no publicly accessible terms and conditions were reviewed, (3) non-compliance could result in consumer complaints to Czech Trade Inspection Authority (ČOI).

Evidence: https://oxyninja.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L0770, https://www.coi.cz/en/

Financials

Three-year financials

Financial Resilience Score: 5/10

OxyNinja is a privately held Czech micro-enterprise with no publicly available financial statements, making a precise quantitative resilience assessment impossible. Qualitatively, the business benefits from an asset-light, software-only model typical of WordPress plugin vendors, with high gross margins (often 80%+), minimal cost of goods, and recurring revenue potential through subscription/renewal models for Motion.page and CoreKit updates. The multi-product portfolio (CoreKit, Woo.Core, Core Framework, Motion.page) provides some diversification, and product-market fit signals are positive — Motion.page was named 'Best Design Plugin of 2022' and reportedly powers 15,000+ sites as of 2024. However, the company faces significant structural risks that constrain its resilience score. Extreme platform dependency on Oxygen Builder is a major vulnerability, especially given the 2024 Oxygen Builder roadmap turbulence (pivot to Breakdance/Oxygen 6). Broader WordPress ecosystem risk from Gutenberg/full-site editing consolidation pressures demand for third-party page-builder add-ons. Key-person risk is acute given the small founder-led team (likely under 10 people). FX exposure exists with USD pricing against CZK cost base. The bootstrapped nature with no disclosed external capital means resilience depends entirely on operating cash flow, and there is no audit requirement or transparency. A middling score reflects the balance of attractive software economics against material concentration and platform risks.

Key strengths: Asset-light software-only model with high gross margins (typically 80%+), Recurring revenue potential from subscription/renewal model (Motion.page, CoreKit updates), Product-market fit signals: Motion.page 'Best Design Plugin of 2022', 15,000+ sites, Multi-product portfolio diversification (CoreKit, Woo.Core, Core Framework, Motion.page), Low fixed cost base typical of Czech micro-team

Risk factors: Extreme platform dependency on Oxygen Builder amid 2024 roadmap pivot to Breakdance/Oxygen 6, Broader WordPress ecosystem risk from Gutenberg/full-site editing consolidation, Key-person risk with small founder-led team (likely under 10 people), FX exposure: USD-priced products vs. CZK cost base, Limited financial transparency; no audited statements required, Bootstrapped with no disclosed external capital; resilience depends entirely on operating cash flow

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report