Bricks Builder

Germany · bricksbuilder.io · 13 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 13 sub-vendors.

Insights

Last updated 2026-08-16 · revision 7

13 direct vendors, 203 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Bricks Builder exhibits medium migration readiness. A significant strength is its core product being built on open-source WordPress, which offers high portability and minimizes proprietary platform lock-in, making a 'lift and shift' migration of its own infrastructure (e.g., license servers, website hosting) relatively straightforward. The company also utilizes standard, widely available third-party services such as Paddle, PayPal, SendGrid, Google Fonts API, Adobe Fonts, OpenStreetMap / Leaflet.js, and Google Maps API. While switching these services requires effort, alternatives are generally available, reducing vendor lock-in risk. However, several factors present significant migration challenges. The underlying WordPress/PHP architecture is not inherently cloud-native, containerized, or microservices-based, which would complicate a full refactoring to a modern cloud-native environment. The 'High risk' GDPR non-compliance and strict data residency requirements for an EU-based company (Cyprus) processing EU resident data will add substantial complexity, cost, and legal scrutiny to any migration strategy, requiring robust data processing agreements and transfer mechanisms. Furthermore, the financial capacity to fund a potentially expensive and complex migration is unknown due to the absence of specific revenue data. The contradictory 'Total Vendors: 0' data point makes it difficult to precisely assess vendor lock-in based on the number of vendors, but the reliance on several critical third-party services implies a moderate level of external dependency.

Compliance

8 in-scope frameworks identified; showing 3.

EU Consumer Rights Directive — Partially Compliant

Bricks Builder sells software licenses to consumers across the EU via distance selling (online). The EU Consumer Rights Directive requires: pre-contractual information, right of withdrawal (14 days for digital content unless consumer consents to immediate delivery), and clear pricing including taxes. The Terms of Service offer a 60-day refund policy (more generous than the 14-day statutory minimum), which is positive. However, the right of withdrawal for digital content and the specific pre-contractual disclosure requirements under the Directive are not explicitly addressed in the ToS. VAT handling is delegated to Paddle. Risk is Medium due to potential gaps in consumer-facing disclosures.

Evidence: https://bricksbuilder.io/terms-of-service/, https://bricksbuilder.io/pricing/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32011L0083

NIS2 (source) — Assessment Required

NIS2 applies to Essential and Important Entities operating in the EU. Codeer Limited (Bricks Builder) is a small software/SaaS company registered in Cyprus. The NIS2 sector categories most relevant to a WordPress visual site builder would be 'Digital Providers' (Annex II — online marketplaces, online search engines, social networking platforms) or potentially 'ICT service management' (Annex I). However, Bricks Builder is primarily a downloadable WordPress theme/plugin product, not a managed ICT service provider or digital infrastructure operator in the NIS2 sense. The critical size threshold is 50+ employees OR €10M+ annual turnover for Important Entities. Bricks Builder appears to be a small team (no public headcount data found), making it likely below the NIS2 size threshold. Risk is Low because the sector match is weak and the company likely falls below size thresholds, but a formal assessment is required to confirm.

Evidence: https://bricksbuilder.io/legal/, https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new, https://www.dmrid.gov.cy/dmrid/dmrid.nsf/All/NIS2

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognized information security standard. While voluntary, it is increasingly expected by enterprise customers and is a strong signal of security maturity. Bricks Builder processes customer personal data, license keys, and payment metadata across multiple digital platforms. The company has experienced at least one publicly known security vulnerability (CVE-2024-25600, a critical RCE vulnerability in Bricks Builder disclosed in February 2024), which underscores the importance of a formal ISMS. The absence of ISO 27001 certification, combined with a known critical vulnerability history, elevates the risk to Medium. Achieving ISO 27001 would significantly reduce reputational and security risk.

Evidence: https://bricksbuilder.io/legal/, https://bricksbuilder.io/privacy-policy/, https://www.cve.org/CVERecord?id=CVE-2024-25600, https://patchstack.com/articles/critical-rce-vulnerability-in-bricks-builder-theme/

Financials

Three-year financials

Financial Resilience Score: 6/10

Bricks Builder, operated by Codeer Limited (Cyprus, HE 383869), is a privately held, bootstrapped WordPress software product with no publicly disclosed financials. Qualitatively, the business exhibits characteristics of a healthy niche software vendor: recurring subscription revenue (USD 79/149/249 annual tiers), lifetime license cash injections (USD 599), high likely gross margins typical of software (80%+), minimal overhead, and no inventory or hardware costs. The product has achieved strong community traction and market position as a leading alternative to Elementor, Oxygen, and Divi since its 2021 launch. However, resilience is constrained by significant concentration risks: 100% single-product dependency, complete reliance on the WordPress ecosystem (itself subject to Automattic/Mullenweg governance uncertainty in 2024-2025), key-person risk tied to founder Thomas Ehrig, and a small team likely under 20 people. Lifetime license sales create long-tail support obligations without matching recurring revenue. The Cyprus incorporation limits third-party financial transparency, and FX exposure exists between USD pricing and EUR-zone operations. Overall, the qualitative signals are positive but unverifiable, warranting a moderate score.

Key strengths: Bootstrapped, low-overhead software model with likely high gross margins (80%+), Recurring annual subscription revenue base creates predictable renewals, Lifetime license tier (USD 599) provides upfront cash injection and deferred-revenue liquidity, Strong community traction reducing paid marketing dependence, Favorable market position capturing share from Elementor, Oxygen, and Divi, Digital-only product with no inventory or hardware costs

Risk factors: 100% single-product concentration on Bricks WordPress theme, Complete platform dependence on WordPress ecosystem, Key-person risk tied to founder Thomas Ehrig, Lifetime licenses create long-tail support obligations without recurring revenue, Regulatory opacity via Cyprus private company structure limits transparency, FX exposure between USD pricing and EUR-zone operating entity, Uncertainty in WordPress ecosystem governance (Automattic/Mullenweg 2024-2025), No public governance or succession documentation

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report