WP SYNTEX

France · polylang.pro · 19 vendors

WP SYNTEX is a French limited liability company that develops and commercializes WordPress plugins, primarily Polylang and Polylang Pro, which enable websites to publish content in multiple languages. They also offer an add-on, Polylang for WooCommerce, to provide multilingual capabilities for e-commerce sites.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 19 sub-vendors.

Insights

Last updated 2026-08-15 · revision 7

19 direct vendors, 180 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

WP SYNTEX exhibits a medium level of migration readiness. The company's internal tech stack, while built around the monolithic WordPress CMS, benefits from modern development practices including CI/CD with GitHub Actions, local development environments (`wp-env`), and robust testing/static analysis tools. This indicates a well-engineered codebase that would be more amenable to migration or refactoring than a legacy system. The use of WordPress REST API and GraphQL also suggests an understanding of API-driven architectures, which can facilitate decoupling. However, significant challenges exist. The core WordPress platform itself is not inherently cloud-native or microservices-based, meaning a full re-platforming would be a substantial undertaking. The most critical constraints are the stringent GDPR and EU data residency requirements, with current hosting in France. Any migration strategy must meticulously ensure continued compliance and data localization. Furthermore, the 'Assessment Required' status for GDPR, SOC2, and ISO 27001, without formal certifications, means these compliance efforts would likely need to be integrated into the migration project, adding complexity and cost. While vendor relationships show geographic diversity across 26 services, the core commitment to the WordPress ecosystem represents a significant architectural dependency.

Compliance

7 in-scope frameworks identified; showing 3.

EU VAT — Compliant

WP Syntex sells digital products (software plugins) to customers across the EU and globally. EU VAT rules for digital services require that VAT be charged based on the customer's location. WP Syntex has a published French VAT number (FR64 819 143 645) and its Terms of Sale explicitly address VAT obligations. The company uses Stripe for payment processing, which supports VAT calculation. Risk is Low as the company appears to have the necessary VAT registration and processes in place.

Evidence: https://polylang.pro/privacy-policy/, https://polylang.pro/terms/

French Data Protection Law — Partially Compliant

France's Loi Informatique et Libertés (LIL), as amended in 2018 and 2019 to align with GDPR, applies directly to WP Syntex as a French-registered company. The law is enforced by the CNIL (Commission Nationale de l'Informatique et des Libertés). WP Syntex has a CNIL Declaration Number (1947430), which is a legacy pre-GDPR filing. Under the post-GDPR LIL framework, formal declarations are no longer required — instead, companies must maintain accountability documentation (Records of Processing Activities, DPIAs where required, etc.). Risk is Medium because the company appears to be operating under the old CNIL declaration regime rather than the updated accountability framework, and no RoPA or DPIA documentation is publicly disclosed.

Evidence: https://polylang.pro/privacy-policy/, https://www.cnil.fr/en/home

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognised information security management standard applicable to any organisation that handles sensitive information. WP Syntex processes customer personal data (names, addresses, emails, payment records, IP addresses, domain names) and provides software products used on 800,000+ websites globally. While ISO 27001 is not legally mandated for WP Syntex's sector, it would be considered best practice for a software company of this profile. Risk is Low because: (1) WP Syntex is a micro-enterprise with limited attack surface; (2) it does not store payment card data directly (delegated to Stripe); (3) its plugin software does not transmit user website data back to WP Syntex; (4) the company has implemented basic security measures (SSL/HTTPS, data breach procedures). However, the absence of ISO 27001 certification means there is no independent verification of its information security controls.

Evidence: https://polylang.pro/privacy-policy/

Financials

Three-year financials

Financial Resilience Score: 7/10

WP SYNTEX operates a category-leading multilingual WordPress plugin (Polylang) with over 800,000 active installations and a strong roster of enterprise/institutional customers including Orange, Rakuten, Disney, UNESCO, Wikimedia and the U.S. Department of State. The business model is based on annual subscription renewals (activation keys) at price points starting around €99/year, producing predictable recurring cash flow with a very lean digital cost base (no physical goods, Stripe-based payments, small team in a low-cost French region). The free version distributed on WordPress.org acts as a permanent zero-cost acquisition funnel, and integrations with WooCommerce and other major plugins reinforce distribution. On the risk side, the company is 100% dependent on the WordPress ecosystem, meaning any move by WordPress Core to natively handle multilingual functionality (referenced in relation to Gutenberg phase 4) could materially reduce the addressable market. Competitive pressure from WPML, TranslatePress and AI-powered SaaS solutions like Weglot constrains pricing power. As a small SARL with only €10,000 share capital and confidential filings, the company also faces key-person risk and limited external financial transparency. Overall, entrenched product position and recurring revenue support a moderately strong resilience score, tempered by ecosystem concentration and competitive dynamics.

Key strengths: Category-leading position with 800,000+ active installs and 4.7/5 rating on WordPress.org, High-quality enterprise/institutional customer references (Orange, Rakuten, Disney, UNESCO, Wikimedia, U.S. State Department), Recurring subscription revenue model via annual activation-key renewals, Very lean digital cost base with fully automated delivery and Stripe payments, Free version on WordPress.org acts as permanent no-cost acquisition funnel, Ecosystem partnerships and integrations (WooCommerce, agencies) reinforce distribution, Active product development with continued release cadence (Polylang 3.8)

Risk factors: 100% dependency on the WordPress ecosystem, Potential WordPress Core native multilingual functionality (Gutenberg phase 4) could reduce TAM, Competitive pressure from WPML, TranslatePress and AI-powered SaaS competitors like Weglot, Small team creates key-person risk, Limited financial transparency due to confidential SARL filings, FX translation exposure with EUR pricing to global (US, UK, APAC) customer base, Very small share capital base (€10,000)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report