Tutor LMS

Latvia · tutorlms.com · 18 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-08-11 · revision 2

18 direct vendors, 190 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Tutor LMS exhibits medium migration readiness. The primary challenge stems from its core technology stack, which is built on WordPress, PHP, and MySQL. While functional, this architecture is not inherently cloud-native, containerized, or microservices-based, meaning a full re-platforming to a modern cloud environment would likely require significant re-architecture and development effort rather than a straightforward lift-and-shift. The extensive list of integrations and add-ons (e.g., OpenAI API, Bunny.net, PayPal, Stripe, Zoom/Google Meet, GrassBlade, Weglot/WPML) implies a complex ecosystem. While vendor diversity is good for resilience, managing the migration of numerous third-party services, each with its own dependencies and potential contractual obligations, could add considerable complexity and cost. The 'Unknown' vendor lock-in risk is a critical factor that could significantly impede migration if key components are tightly coupled to specific vendors. Furthermore, the absence of data regarding regulatory environment, data residency requirements, and financial stability (ability to fund a migration) makes a comprehensive assessment of migration challenges and opportunities difficult. Opportunities for migration include the use of REST API and React, which suggest some modularity that could facilitate a phased or hybrid migration approach. The open-source nature of WordPress also offers flexibility in hosting choices.

Compliance

8 in-scope frameworks identified; showing 3.

PCI DSS (source) — Assessment Required

Tutor LMS processes payments through Stripe, PayPal, and major credit cards (MasterCard, Visa, American Express). Risk is MEDIUM because: (1) payment card data is processed through the platform; (2) PCI DSS compliance is required for any entity that stores, processes, or transmits cardholder data; (3) if Tutor LMS relies entirely on Stripe/PayPal for payment processing (tokenization), it may qualify for SAQ A (lowest compliance tier); (4) however, if any cardholder data flows through Tutor LMS servers, higher PCI DSS tiers apply; (5) non-compliance can result in fines from card networks and loss of payment processing ability.

Evidence: https://tutorlms.com/ecommerce/, https://tutorlms.com/terms/, https://www.pcisecuritystandards.org/, https://stripe.com/docs/security

Latvia Personal Data Processing Law — Assessment Required

Latvia's national data protection law implements and supplements GDPR at the national level. As a Latvian-registered company, Tutor LMS is subject to oversight by Latvia's Data State Inspectorate (Datu valsts inspekcija - DVI). Risk is HIGH because: (1) the DVI has enforcement powers including fines and corrective orders; (2) Latvia's national law includes specific provisions on employee data, public sector data, and special categories; (3) no evidence of DVI registration or compliance documentation was found; (4) the DVI has been active in GDPR enforcement within Latvia.

Evidence: https://www.dvi.gov.lv/en, https://likumi.lv/ta/en/en/id/300099, https://tutorlms.com

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA for cloud service providers and SaaS companies. Tutor LMS operates a cloud-hosted SaaS platform serving 100,000+ eLearning websites and processes customer and learner data. Enterprise and institutional customers (schools, academies, coaching businesses) increasingly require SOC 2 Type II reports as a vendor due diligence requirement. Risk is MEDIUM because: (1) absence of SOC 2 certification may limit Tutor LMS's ability to win enterprise contracts; (2) the platform handles payment data, learning records, and personal information at scale; (3) no SOC 2 report was found publicly, suggesting this has not been pursued; (4) as the platform grows to serve larger institutional clients, the absence of SOC 2 becomes a competitive and risk management gap.

Evidence: https://tutorlms.com, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

Financials

Financial Resilience Score: 6/10

Tutor LMS, a product of Themeum, is a privately held WordPress plugin company with no publicly disclosed financial statements. The assessment is therefore qualitative and inferred from the business model. The company benefits from a recurring revenue model based on annual and lifetime licenses for Tutor LMS Pro, plus add-ons and subscriptions, producing predictable renewal revenue typical of the WordPress plugin ecosystem. A claimed installed base of 100,000+ live sites provides a strong free-to-paid conversion funnel via WordPress.org, and the customer base is diversified across many small customers (course creators, coaches, schools, agencies), limiting concentration risk. The business is capital-light with digital delivery, no inventory, and a largely remote workforce. Product breadth is expanding (Course Builder, AI Studio, Certificate Builder, native e-commerce, subscriptions, memberships), increasing ARPU per customer. However, the company faces significant risks from platform dependency on WordPress, competitive pressure from LearnDash, LifterLMS, MasterStudy, and SaaS platforms like Kajabi, Teachable, and Thinkific. GPL licensing exposes it to nulled-plugin redistribution, and governance is opaque with no public filings or disclosed ownership. FX risk exists if billed in USD but costs are in BDT/EUR, and there is likely key-person/small-team dependence typical of bootstrapped plugin businesses.

Key strengths: Recurring revenue model via annual/lifetime licenses and add-ons, Large installed base of 100,000+ live sites, Diversified small-customer base limits concentration risk, Capital-light digital delivery business model, Expanding product breadth increases ARPU

Risk factors: Platform dependency on WordPress ecosystem, Strong competition from LearnDash, LifterLMS, MasterStudy, Kajabi, Teachable, Thinkific, GPL licensing exposes product to nulled-plugin redistribution, Opaque governance with no public filings or disclosed financials, FX/cross-border currency mismatch risk (USD revenue vs BDT/EUR costs), Key-person and small-team dependence

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report