Skip to content

Open-source business platforms

Open-source business platforms

We counted what can be counted about the platforms European companies run their websites, shops and back offices on. The interesting part is what cannot be counted — and how little effort it takes to find the rest.

What was measured, and what was not

Four different quantities get confused in numbers like these, and the difference matters more than the total.

  1. 1

    Detected public websites — what a technology-data provider currently associates with a product. This is what the table below shows.

  2. 2

    Installations — independently operated deployments. Several websites can share one; one deployment can host many tenants.

  3. 3

    Organisations — companies, institutions and sole traders. One organisation can run several installations.

  4. 4

    Users — accounts or people. A vendor’s user claim cannot be turned into installations without further evidence.

The scale, and the part the scale misses

Across eighteen platforms, 14,647,101 European websites were detected running one of them. That counts websites rather than companies, the provider’s definition of Europe is wider than the EU27, and WordPress’s share includes personal sites.

It is also the floor, not the ceiling. Two of the eighteen have no defensible public count at all — Dolibarr and metasfresh are business systems behind a login, so there is nothing public to detect. ERPNext shows 39 and SuiteCRM 402, which are visible samples rather than adoption figures, while Dolibarr’s own maintainers estimate 200,000 organisations worldwide.

So the platforms a company runs its operations on are precisely the ones this method cannot see. The website numbers are large; the invisible population is the one that holds the invoices.

The eighteen platforms

European detected websites and where each product publishes its security news. Source: BuiltWith, retrieved 2026-10-03.

PlatformAreaEuropean websites detectedSecurity news published
WordPressCMS11,394,339Core releases; plugins separately
WooCommerceCommerce1,792,645Repository advisories (GHSA)
JoomlaCMS484,353Security centre; extensions separately
MatomoAnalytics339,271Changelog; advisory list was empty
TYPO3CMS174,787Official security bulletins
DrupalCMS162,657Two tracks: core and contributed
PrestaShopCommerce113,026Repository advisories (GHSA)
OdooERP/CRM50,476Its own CNA; repository list empty
Magento familyCommerce48,375Parent vendor bulletins
NextcloudCollaboration32,781Dedicated advisory repository
Shopware 6Commerce22,391Repository advisories (GHSA)
MoodleLearning16,014Official security bulletins
MauticMarketing automation14,864Repository advisories (GHSA)
GLPIITSM681Repository advisories (GHSA)
SuiteCRMCRM402Repository advisories, ahead of CVE records
ERPNextERP39Two projects must both be watched
DolibarrERP/CRMno public countCVEs exist; maintainers are not a CNA
metasfreshERP/supply chainno public countNo product CVE found

How easily these are found

No tooling, no scanning, no privileged access. Two ordinary search queries, and Odoo makes the point because it is a business system rather than a blog.

The software announces itself

Many installations keep the default footer, and that footer is a search term. One query returns a list of organisations running the product.

"Powered by Odoo" -site:odoo.com

The front door is at a predictable address

Default login paths are the same everywhere. Combined with the product name, that returns sign-in pages rather than marketing pages.

inurl:web/login "Odoo"

Adding a single country restriction narrows either query to one market. That is the whole technique, and it is in every search-operator tutorial — which is the point: this is not a capability anybody has to acquire.

What this does not show is a vulnerable version. A footer or a login page says a product is running, not which release — and we publish neither credentials, exports nor exploit paths. Testing anything you do not own needs permission.

Run it against your own estate

The same query, pointed at your own domain, is a five-minute inventory. It is also the most common way companies discover an installation nobody remembered.

site:yourcompany.com "Powered by Odoo"

Repeat it for each product you think you run, and for each one you have inherited through an acquisition or an agency. A result you did not expect is the finding.

Why no single feed covers you

Eighteen products publish security news in 13 different ways. Core and plugins are separate sources for some; others route through a parent vendor; one maintainer states plainly that they are not a CVE Numbering Authority and do not publish CVE reports themselves; another had no product-specific CVE at all when we looked.

A company running five of these has five habits to maintain, in five formats, with no common schedule. That is not a discipline problem. There is no single place to watch.

And a growing share of fixes carry no CVE at all. Shopware's most recent critical releases were published as repository advisories without one; ERPNext disclosed sixty-eight in eight weeks, almost none with a CVE; eleven of sixteen recent WordPress core advisories had none. So watching CVE feeds alone — the obvious thing to automate — misses them.

Two things this table is not. More published vulnerabilities does not mean a less secure product — it often means a more organised disclosure process. And an empty advisory feed is not evidence a product is untracked; Odoo publishes through its own channel while its repository advisory list was empty when we checked.

Platform counts retrieved 2026-10-03 from BuiltWith. Advisory practices checked the same week, and re-verified first-hand on 2026-10-04 against the live advisory data. Both change; the figures here are a measurement with a date on it, not a standing fact.

Vulnerability alerts

A weekly summary of what was published about the products you follow. One email, on the same day each week, and nothing in a quiet week.

Start receiving alerts