WordPress
United States · wordpress.org · 15 vendors
The WordPress Foundation is a 501(c)(3) public charity established to ensure free and perpetual access to the open-source WordPress software. Its mission is to democratize publishing through open-source, GPL software. The Foundation is responsible for protecting the WordPress, WordCamp, and related trademarks.
Resilience scores
- Digital Sovereignty: 80
- Digital Resilience: 9
- Financial Resilience: 7
Disruption prediction
WordPress has a 43% probability of disruption in the next 6 months.
9 of WordPress's 15 vendors monitored for disruptions.
Technology vendors
- Alphabet Inc. — Technology — United States
- Bluehost — Technology — United States
- Prometheus — United States
- and 20 more
Services catalogue
15 services in catalogue across 6 categories; runs on 15 sub-vendors.
- Plugin directory
- Website Statistics
- WooCommerce
Insights
Last updated 2026-06-10 · revision 8
15 direct vendors, 202 subvendors
Direct vendors by controlling owner country (sample)
- United States: 12
- Denmark: 1
- France: 1
Subvendors by controlling owner country (sample)
- Switzerland: 3
- Denmark: 4
- Poland: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
WordPress exhibits strong migration readiness, largely due to its minimal direct vendor lock-in and robust financial position. The reported 'Total Vendors: 0' for core operations is a substantial advantage, as it eliminates the complexities of untangling vendor contracts and technology dependencies often associated with large-scale migrations. This allows for greater flexibility in choosing new platforms or architectures. Financially, the company's strong revenue and valuation provide ample resources to fund significant migration efforts. From a technology perspective, while the core WordPress platform is built on traditional PHP/MySQL, the presence of a comprehensive REST API and the modular Gutenberg Block Editor facilitates decoupling and modernization, making it more amenable to cloud-native or microservices architectures. The open-source nature of its key technologies also ensures broad compatibility and community support across various hosting environments. However, challenges exist: the core PHP/MySQL architecture may require significant refactoring for a full cloud-native transformation. Furthermore, the 'Assessment Required' status for SOC2 and ISO 27001 could pose hurdles if migrating to highly regulated cloud environments that demand these certifications. Data residency for WordPress.org's own user data, with its global user base and GDPR compliance, would also require careful planning during any migration.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
WordPress.org explicitly states compliance with GDPR legislation in their privacy policy. As a US-based organization that processes personal data of EU/EEA residents through their global user base, forums, and events, GDPR applies. The medium risk reflects their proactive compliance stance but the complexity of managing an open-source ecosystem with global contributors and users.
Evidence: https://wordpress.org/about/privacy/
SOC 2 (source) — Assessment Required
As a platform that hosts user data and provides services to millions of users globally, SOC2 compliance would be beneficial for demonstrating security controls. However, as an open-source foundation rather than a commercial cloud service provider, SOC2 may not be mandatory but could be valuable for trust and enterprise adoption.
ISO 27001 (source) — Assessment Required
Given WordPress's role in powering 43% of websites globally and handling significant user data, information security management is critical. ISO 27001 certification would demonstrate robust security practices, though it's not legally mandated for open-source foundations.
Evidence: https://wordpress.org/about/security/
Financials
Three-year financials
- 2023:
- 2022: revenue US$500M
- 2021:
Financial Resilience Score: 7/10
Automattic, the commercial entity behind WordPress.com and the broader WordPress ecosystem, demonstrates strong qualitative financial resilience despite limited public disclosure. The company benefits from a dominant market position, with WordPress powering over 40% of all websites globally, creating a substantial moat for its commercial offerings. Its diversified product portfolio spans consumer hosting, enterprise hosting, e-commerce (WooCommerce), security/performance tools (Jetpack), social platforms (Tumblr), and messaging apps (Beeper, Texts), reducing dependency on any single revenue stream. The company is well-capitalized, having raised approximately US$288 million in its Series E round in February 2021 at a reported ~US$7.5 billion valuation, backed by reputable investors including Salesforce Ventures, BlackRock, and Insight Partners. The open-source WordPress.org project serves as a powerful funnel into Automattic's paid services, providing a sustainable customer acquisition advantage. However, resilience is tempered by significant risks. The lack of audited financial transparency makes independent verification difficult. The 2024-2025 public dispute with WP Engine raised governance concerns and triggered an employee buyout program where approximately 8.4% of staff departed. Tumblr has reportedly been loss-making, and the company faces competitive pressure from Shopify, Wix, Squarespace, and headless CMS vendors like Contentful and Sanity.
Key strengths: Dominant market position with WordPress powering 40%+ of all websites globally, Diversified product portfolio across hosting, e-commerce, security, and consumer apps, Well-capitalized with multiple large funding rounds (Series D ~US$300m in 2019, Series E ~US$288m in 2021), Strong investor backing from Salesforce Ventures, BlackRock, and Insight Partners, Open-source community moat creating sustainable customer acquisition funnel, Reported ~US$7.5 billion valuation at last funding round
Risk factors: Lack of audited financial transparency as a private company, Governance overhang from 2024-2025 WP Engine dispute, Employee departures (~8.4% of staff) via late-2024 alignment offer buyouts, Tumblr reportedly loss-making since 2019 acquisition, Concentration risk on WordPress ecosystem health, Competitive pressure from Shopify, Wix, Squarespace, and headless CMS vendors, Community/governance debate over relationship between WordPress.org and Automattic
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.