Metafizzy

United States · flickity.metafizzy.co · 2 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 2 sub-vendors.

Insights

Last updated 2026-07-01 · revision 1

2 direct vendors, 77 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Metafizzy's migration readiness is assessed as moderate, largely due to an unclear internal infrastructure and significant reliance on external services. The company's tech stack, while featuring modern JavaScript, also includes jQuery and Bower, and lacks explicit mention of cloud-native components such as containerization (e.g., Docker, Kubernetes) or microservices architecture, suggesting a potentially more traditional or monolithic internal setup for their operational infrastructure (e.g., license management, website hosting). This could lead to increased complexity and effort during a migration to modern cloud environments. A major challenge is the complete absence of financial stability data (revenue concentration, growth history), which makes it impossible to assess the company's capacity to fund a potentially costly migration. Furthermore, despite the "Vendor Relationships" data indicating "Total Vendors: 0", Metafizzy heavily relies on several US-based external services like Gumroad for e-commerce, GitHub for distribution, and Mailchimp for marketing. Migrating away from these critical dependencies would effectively require re-platforming core business functions, representing a form of de facto vendor lock-in and adding significant complexity and cost to any migration effort. The lack of specified regulatory environment and data residency requirements also introduces potential unknown compliance hurdles during a migration.

Compliance

4 in-scope frameworks identified; showing 3.

CPRA — Assessment Required

The California Consumer Privacy Act (CCPA) and its amendment CPRA apply to for-profit businesses that meet specific thresholds: annual gross revenue over $25M, buy/sell/receive/share personal information of 100,000+ consumers/households, or derive 50%+ of annual revenue from selling personal information. Metafizzy's license pricing ($25–$320 per license) and apparent micro-business scale make it very unlikely to meet the $25M revenue threshold. However, if it processes California residents' data (likely, given its US base and global customer reach), it should be aware of these laws. Risk is low due to likely failure to meet applicability thresholds.

Evidence: https://flickity.metafizzy.co, https://oag.ca.gov/privacy/ccpa

US Export Control — Assessment Required

Metafizzy's commercial license agreement explicitly states that licensees must 'comply with all applicable laws and regulations with respect to the Software, including without limitation all export control laws and regulations.' This indicates Metafizzy is aware of export control obligations. JavaScript UI widget libraries are generally classified as EAR99 (not subject to export licensing requirements) or fall under License Exception TSU for publicly available software. Risk is low as the software is non-military, non-dual-use, and widely publicly available.

Evidence: https://flickity.metafizzy.co/license, https://www.bis.doc.gov/index.php/regulations/export-administration-regulations-ear

ISO 27001 (source) — Assessment Required

ISO 27001 is an international information security management standard. While it is not legally mandated for Metafizzy's business type, it could be relevant as a best-practice framework for protecting intellectual property (source code), customer license data, and business information. However, for a micro-business of Metafizzy's apparent size, ISO 27001 certification is rarely pursued and is not expected by the market for UI widget vendors. The risk of not having ISO 27001 is low given the company's size, product type, and customer expectations.

Evidence: https://flickity.metafizzy.co, https://www.iso.org/isoiec-27001-information-security.html

Financials

Three-year financials

Financial Resilience Score: 5/10

Metafizzy is a bootstrapped, single-founder indie software business with no public financial disclosures. It benefits from very low overhead as a solo/micro operation with no disclosed office footprint or additional employees, and it has a diverse portfolio of widely-used JavaScript libraries (Flickity, Isotope, Packery, Infinite Scroll, Draggabilly, imagesLoaded) that reduces single-product risk. The company has a long track record of over a decade, demonstrating self-sustaining viability, particularly signaled by the founder's 2019 return to full-time work on Metafizzy. However, the business faces material risks including significant key-person dependency on founder David DeSandro, technology obsolescence as modern frameworks (React, Vue, Svelte) and native CSS features reduce demand for third-party JS libraries, slowing release cadence (most recent visible release from Feb 2022), potential piracy or GPLv3 substitution avoiding commercial licenses, and an inherently small absolute revenue base. No debt or investor obligations are disclosed, suggesting the business is financially independent but thin compared to venture-backed peers.

Key strengths: Very low overhead as a solo/micro operation, Diverse product portfolio of widely-used JS libraries, Long track record of over a decade, Recurring commercial-license demand from agencies and enterprises, No debt or investor obligations disclosed (bootstrapped)

Risk factors: Key-person risk tied to founder David DeSandro, Technology obsolescence with shift to modern frameworks and native CSS, Slowing release cadence (most recent release Feb 2022), Piracy and GPLv3 free-tier substitution, Small absolute revenue base

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report