Designs & Code

United Kingdom · www.designsandcode.com · 11 vendors

Designs and Codes, LLC is a company that crafts digital solutions for the internet. They specialize in custom WordPress solutions, responsive website design, database management, and custom coding using various web technologies. The company also offers API development, user interface and experience design, brand identity services, and digital illustrations and animations.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-07-30 · revision 1

11 direct vendors, 168 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The company demonstrates medium-low migration readiness. The primary challenge stems from its core tech stack, which is heavily reliant on WordPress and PHP. This typically implies a more monolithic architecture that is not inherently cloud-native, containerized, or microservices-based, necessitating substantial re-architecture for a modern cloud migration. The products' deep integration with the broader WordPress ecosystem (e.g., WooCommerce, ACF, Elementor) creates significant platform lock-in, making a migration away from this ecosystem a complex and potentially costly undertaking. Critical information regarding financial stability (to fund a migration), regulatory environment, and data residency requirements is not provided, introducing significant unknowns and potential hurdles. The vendor lock-in risk is "Unknown," which is a crucial factor as high lock-in can severely impede migration efforts. While the company uses 15 services from geographically diverse countries, the specific nature of these services and their potential for lock-in are not detailed. On the positive side, the use of GitHub for its internal tech stack suggests good version control and collaborative development practices, which can facilitate a more structured migration process.

Compliance

6 in-scope frameworks identified; showing 3.

Consumer Rights Act 2015 — Assessment Required

As a UK-based company selling digital products (WordPress plugins) to consumers, Designs & Code is subject to the Consumer Rights Act 2015 and the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013. These require clear pre-contractual information, cancellation rights for digital content (with specific rules on waiving the 14-day cooling-off period), and that digital content meets satisfactory quality standards. Risk is MEDIUM because: (1) the company sells to both businesses and consumers globally; (2) failure to provide required pre-contractual information or honour cancellation rights can result in Trading Standards enforcement; (3) the company does publish a Refund Policy on the searchandfilter.com site, indicating some awareness of these obligations.

Evidence: https://searchandfilter.com/refund-policy/, https://support.searchandfilter.com/

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA applicable to service organisations that store, process, or transmit customer data in the cloud. Designs & Code provides SaaS-adjacent services (hosted plugin licensing, support portal, customer accounts with payment data). While SOC 2 is not legally mandated, enterprise customers — particularly those in regulated industries — increasingly require SOC 2 Type II reports from their software vendors. Risk is MEDIUM because: (1) the company processes customer payment and account data; (2) absence of SOC 2 certification may limit enterprise sales opportunities; (3) the company's customer base (WordPress site owners globally) may include regulated entities that require vendor SOC 2 compliance; (4) no SOC 2 report is publicly available.

Evidence: https://www.designsandcode.com, https://support.searchandfilter.com/

Privacy and Electronic Communications Regulations 2003 — Assessment Required

PECR implements the EU ePrivacy Directive in UK law and governs the use of cookies, electronic marketing, and communications data. Designs & Code operates websites that use cookies (including Google Analytics, confirmed on the support subdomain). Risk is MEDIUM because: (1) the company must obtain valid consent for non-essential cookies (analytics, marketing) under PECR; (2) the support subdomain implements a GDPR Cookie Compliance plugin with consent management; (3) the main designsandcode.com domain does not appear to have a visible cookie consent banner; (4) ICO has issued enforcement notices and fines for PECR violations, including cookie consent failures.

Evidence: https://support.searchandfilter.com/, https://www.designsandcode.com

Financials

Three-year financials

Financial Resilience Score: 6/10

Designs & Code appears to be a mature, bootstrapped UK WordPress plugin business with approximately 10 years of operating history, which is notable in a niche where many plugin shops fail within 2-3 years. The company operates a recurring-revenue subscription model via Search & Filter Pro with a base of 50,000-60,000 active users, providing predictable cash flow. Its low fixed-cost structure (small distributed team, no physical footprint) supports resilience. However, the business faces meaningful risks including single-product concentration (Search & Filter product family likely represents >80-90% of revenue), complete platform dependency on WordPress, and key-person risk given the small team led by founder Ross Morsali. Competitive pressure from FacetWP, FiboSearch, and native WooCommerce filter blocks poses ongoing threats. No public financial statements are available as the company likely files under the UK micro-entity or small company regime, limiting transparency for creditors and enterprise buyers. The score reflects a stable but small-scale operation with limited financial visibility.

Key strengths: Long operating history (~10 years) indicating durable product-market fit, Recurring revenue model with 50,000-60,000 active users, Low fixed-cost base with small distributed team, Strong brand within WordPress filtering niche with ecosystem integrations (WooCommerce, Elementor, ACF, Divi, Beaver Builder, WPML), Positive third-party signals: 4.6/5 WordPress.org rating, 200+ Trustpilot reviews, 100,000+ active installs of free plugin acting as funnel to Pro

Risk factors: Single-product concentration in Search & Filter product family, 100% platform dependency on WordPress ecosystem, Key-person risk with small team led by founder, Limited public financial transparency as UK small/micro-entity, Competitive pressure from FacetWP, FiboSearch, and native WooCommerce filters, Support-cost scaling challenges with large user base and small team, Risk of costly rewrites from WordPress architectural shifts (evidenced by multi-year v3 rewrite)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report