Qode Interactive

Serbia · qodeinteractive.com · 14 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 14 sub-vendors.

Insights

Last updated 2026-07-27 · revision 1

14 direct vendors, 172 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Qode Interactive demonstrates medium migration readiness. A key strength is the existing use of AWS and AWS Application Load Balancer, indicating familiarity with cloud infrastructure and providing a foundational advantage for cloud migration. The core technologies, WordPress and PHP, are highly portable and widely supported, which can simplify certain aspects of a migration. However, significant challenges exist due to the lack of information regarding the company's financial stability, which is crucial for funding a potentially costly migration effort. The current tech stack, while leveraging AWS, does not explicitly mention modern cloud-native patterns such as containerization (e.g., Docker, Kubernetes) or microservices, suggesting a potentially more monolithic architecture that could increase migration complexity. Unspecified regulatory environment and data residency requirements could introduce substantial hurdles if strict compliance is necessary post-migration. The provided data on 'Total Vendors: 0' contradicts other vendor information (16 services, diverse vendor HQs); assuming vendors exist, the unknown vendor lock-in risk is a major concern, as heavy reliance on specific vendors or complex contracts could impede migration flexibility. The presence of 16 services also suggests a potentially complex ecosystem of integrations that would require careful planning during any migration initiative.

Compliance

8 in-scope frameworks identified; showing 3.

EU ePrivacy Directive — Partially Compliant

Risk is MEDIUM because: (1) The company is incorporated in Cyprus (EU) and serves EU users, making the ePrivacy Directive applicable. (2) The website deploys a cookie consent management platform (GDPR Cookie Consent plugin) with categorized consent options, indicating awareness and partial implementation. (3) However, the cookie table reveals advertising cookies (Facebook 'fr' cookie, 3-month duration) and multiple Google Analytics tracking cookies that require explicit opt-in consent under ePrivacy rules. (4) The presence of AWSALB load balancer cookies and Cloudflare cookies as 'necessary' is generally acceptable. (5) Risk is medium because the consent mechanism exists but the adequacy of pre-consent cookie loading and the granularity of consent cannot be fully verified without live testing.

Evidence: https://qodeinteractive.com/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058

NIS2 (source) — Assessment Required

NIS2 risk is MEDIUM for the following reasons: (1) QODE LTD is incorporated in Cyprus (EU member state), so NIS2 geographic scope is met. (2) The company operates as a digital provider — specifically a digital marketplace/online platform and potentially an ICT service provider — categories that may fall under NIS2 'Important Entities' (digital providers: online marketplaces, online search engines, cloud computing services). (3) The company has 100+ employees and serves 750,000+ customers, likely exceeding the medium enterprise threshold (50+ employees or €10M+ turnover). (4) However, the primary classification as a WordPress theme/plugin vendor rather than a critical infrastructure operator reduces the severity. (5) Cyprus has transposed NIS2 into national law, and enforcement is active. (6) The risk is medium rather than high because the sector classification (digital marketplace vs. critical infrastructure) requires formal assessment, and the company's exact revenue figures are not publicly confirmed.

Evidence: https://qodeinteractive.com/about/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.dsa.gov.cy/, https://digital-strategy.ec.europa.eu/en/policies/nis2-directive

ISO 27001 (source) — Assessment Required

Risk is MEDIUM because: (1) Qode Interactive processes sensitive customer data including account credentials, payment information, and behavioral data for 750,000+ users. (2) As a digital product company, information security incidents (data breaches, unauthorized access) could have significant reputational and financial consequences. (3) ISO 27001 certification would demonstrate a systematic approach to information security management, which is increasingly expected by enterprise customers and required under GDPR's 'appropriate technical and organizational measures' obligation. (4) Without ISO 27001, the company relies on undocumented security practices, increasing the risk of security gaps. (5) The risk is medium rather than high because ISO 27001 is voluntary and many companies of similar size operate without formal certification.

Evidence: https://qodeinteractive.com/, https://www.iso.org/isoiec-27001-information-security.html

Financials

Three-year financials

Financial Resilience Score: 6/10

Qode Interactive is a long-established (founded 2011) private Serbian WordPress theme developer with a genuine market-leading product (Bridge theme, #1 best-selling creative theme on ThemeForest) and a diversified catalog of 600+ themes across five Envato Power Elite author profiles. Its 14+ year track record, low-cost Serbian operating base against USD-denominated marketplace revenue, and expansion into plugins/add-ons (Qi Addons for Elementor, Qi Blocks for Gutenberg) suggest positive cumulative cash generation and healthy margins. However, resilience is constrained by heavy platform concentration on ThemeForest/Envato as the primary sales channel, exposing the company to marketplace policy and algorithm changes. The broader premium WordPress theme category has faced structural headwinds since ~2019-2020 from free themes bundled with page builders, SaaS website builders (Wix, Squarespace, Webflow, Shopify), and emerging AI site builders. The WordPress core shift toward Gutenberg/full-site editing also compresses demand for traditional multipurpose themes. As a private Serbian d.o.o., transparency is limited to APR filings, and audited financials were not accessible in this research session, adding uncertainty to any resilience assessment.

Key strengths: Market-leading Bridge theme with 10+ year sales track record on ThemeForest, Diversified catalog of 600+ themes across dozens of end-industries, Five Envato Power Elite author profiles providing marketplace ranking benefits, Low-cost Serbian development base vs. USD-denominated marketplace revenue, Recurring revenue from theme updates, plugin licensing, and add-on sales, 14+ year operating history implying positive cumulative cash generation, Strategic pivot into Elementor add-ons and Gutenberg blocks

Risk factors: Heavy platform concentration on ThemeForest/Envato as single primary sales channel, Structural decline in premium WordPress theme category since ~2019-2020, Competition from free themes, SaaS website builders (Wix, Squarespace, Webflow), and AI site builders, WordPress Gutenberg/full-site-editing transition compressing demand for multipurpose themes, FX exposure (USD revenue vs. RSD/EUR costs), Limited financial transparency as private company, Serbia's non-EU status introducing regional risk premia, Marketing customer counts (300k vs 750k vs 1M) are inconsistent and unaudited

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report