VeronaLabs

Estonia · veronalabs.com · 21 vendors

VeronaLabs is an independent company that develops popular WordPress plugins such as WP Statistics, WP SMS, and WP SlimStat. Since 2018, they have empowered over 750,000 websites with privacy-friendly analytics and communication tools. The company prioritizes quality, innovation, and user privacy in its offerings.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 21 sub-vendors.

Insights

Last updated 2026-07-29 · revision 6

21 direct vendors, 265 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

VeronaLabs demonstrates a medium level of migration readiness, leaning towards the lower end due to several architectural and regulatory challenges. Strengths include expertise in widely adopted technologies like WordPress, PHP, and MySQL, which facilitates migration to managed services or within the WordPress ecosystem. The company's products are designed with GDPR/CCPA/PECR compliance in mind, which is a significant advantage for handling and migrating data in accordance with regulatory requirements. The self-hosted data architecture provides full control over data, simplifying export and transfer processes. Additionally, the use of Cloudflare and Astro for its WSMS website frontend, along with REST API and webhooks support in WSMS, indicates some adoption of modern web infrastructure and integration capabilities. However, significant challenges exist. The core tech stack, heavily reliant on WordPress, PHP, and MySQL, can be monolithic, making a full migration to a truly cloud-native, microservices architecture complex and potentially requiring extensive refactoring. Strict EU data residency requirements under GDPR will constrain choices for cloud providers and regions, adding complexity to infrastructure planning. A major impediment is the 'Assessment Required' status for critical regulations such as GDPR, NIS2, SOC2, and ISO 27001. Addressing these compliance gaps would be a prerequisite or a substantial part of any migration effort, adding significant cost and time. Financial capacity to fund a potentially expensive migration cannot be assessed due to the absence of revenue data. The 'Unknown' vendor lock-in risk, despite geographic diversity across 7 countries for 53 services, means potential dependencies and contract complexities could hinder migration flexibility.

Compliance

7 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Estonian law) applies to Essential Entities and Important Entities operating in the EU. VeronaLabs is an EU-based technology company. The key question is whether it falls into a listed NIS2 sector and meets the size threshold (50+ employees OR €10M+ annual turnover for 'medium enterprise' classification). VeronaLabs' primary products are WordPress analytics plugins (WP Statistics, WP Slimstat) and an SMS/2FA plugin (WSMS). These could potentially be classified under 'digital providers' (specifically 'online marketplaces' or 'online search engines' are listed, but analytics plugin vendors are not explicitly named) or 'ICT service management (managed service providers)'. However, VeronaLabs appears to be a small software company — their website reports 700K+ active users but gives no employee count or revenue figures. If they are below the 50-employee / €10M turnover threshold, they would be exempt as a micro or small enterprise. Risk is assessed as Low because: (a) their sector (WordPress plugin development) is not among the clearly listed NIS2 sectors; (b) they are likely a small enterprise below the size threshold; (c) no regulatory action or NIS2 registration has been identified. Assessment is required to confirm employee count, revenue, and precise sector classification.

Evidence: https://veronalabs.com/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It is relevant to any organization that manages sensitive information, including software companies handling customer data, authentication credentials, and analytics data. VeronaLabs' WSMS product handles SMS delivery and two-factor authentication — security-critical functions where a breach could have significant consequences for end users. Their analytics products (WP Statistics, WP Slimstat) process website visitor data for 700K+ active installations. While ISO 27001 is voluntary, it is increasingly expected by enterprise customers and is a strong signal of security maturity. Risk is Medium because: (a) no ISO 27001 certification has been found; (b) their security-sensitive products (2FA/SMS) create meaningful information security obligations; (c) as an EU company, ISO 27001 aligns with GDPR's Art. 32 requirement for 'appropriate technical and organisational measures'; (d) the company's privacy-first positioning creates reputational risk if a security incident occurs without demonstrable ISMS.

Evidence: https://veronalabs.com/, https://wp-statistics.com/

GDPR (source) — Partially Compliant

VeronaLabs OÜ is headquartered in Tallinn, Estonia — an EU member state — making GDPR unconditionally applicable. Their published privacy policy demonstrates meaningful compliance effort: they cite correct legal bases (Art. 6(1)(a) consent and Art. 6(1)(f) legitimate interest), enumerate all eight GDPR data-subject rights, implement a cookie-consent banner, and name the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) as the competent supervisory authority. However, several gaps elevate risk to Medium: (1) the privacy policy is marked 'noindex' in robots meta, reducing discoverability; (2) no Data Protection Officer (DPO) is publicly identified or contact provided — while a DPO may not be mandatory for a company of this size unless processing is large-scale or systematic, its absence should be assessed; (3) data transfers to Google (US) and Microsoft (US) rely on Standard Contractual Clauses (SCCs) but no Transfer Impact Assessment (TIA) documentation is publicly available; (4) retention periods for some categories (e.g., user account data) are vague ('until you request deletion'); (5) no Records of Processing Activities (RoPA) are publicly referenced. Enforcement by the Estonian DPA is active and fines, while typically lower than those issued by larger EU DPAs, are real. The company's core product (WP Statistics) is explicitly marketed as GDPR-compliant, creating reputational and legal exposure if their own practices fall short.

Evidence: https://veronalabs.com/privacy-policy/, https://veronalabs.com/, https://wp-statistics.com/privacy-policy, https://wp-statistics.com/resources/what-we-collect

Financials

Three-year financials

Financial Resilience Score: 6/10

VeronaLabs OÜ demonstrates qualitative signs of financial resilience despite the absence of verified figures. The company has an established product-market fit with WP Statistics (600K+ active installs) and a portfolio of three complementary WordPress plugins totaling 700K+ active users and 35M+ downloads. Its privacy-first, GDPR-compliant positioning benefits from regulatory tailwinds in the EU post-Schrems II, and its Estonian OÜ structure combined with a likely small, remote team implies a low fixed-cost base and high operating leverage. Premium/Pro tiers across products suggest sticky subscription-style revenue. However, resilience is constrained by significant risks: 100% dependency on the WordPress ecosystem, competition from Jetpack Stats, MonsterInsights, Fathom, and Plausible, key-person risk typical of small OÜs, limited financial transparency, and FX mismatch between USD-earned revenue and EUR-denominated costs. Without access to Estonian Business Register filings, a precise resilience score cannot be validated; the mid-range score reflects a stable niche business with meaningful concentration and scale risks.

Key strengths: Established product-market fit with WP Statistics (600K+ active installs), Recurring subscription revenue potential from Pro/premium tiers, Regulatory tailwind from GDPR and Schrems II favoring privacy-first analytics, Low fixed-cost base as a software-only Estonian OÜ, Diversified product mix across three distinct plugins, 35M+ cumulative downloads and 700K+ active users

Risk factors: 100% platform concentration in WordPress ecosystem, Competitive pressure from Jetpack Stats, MonsterInsights, Fathom, Plausible and others, Small entity and key-person risk in a small founding team, Limited financial transparency and no institutional investor coverage, FX exposure between USD revenue and EUR costs

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report