coder.com ↗ · required email domain for this vendor's users
3 of 5 independent trust signals established
Coder has 3 dimensions with established evidence. The rest have not been confirmed yet.
Not yet established: Independently verified · Operating durability
Has anyone other than the vendor confirmed this?
1 independent source(s) corroborate this vendor's claims.
Is this a real, durable business?
How long this vendor has been operating, and who stands behind them.
What do they do when something goes wrong?
What their public record shows about handling vulnerabilities and outages.
Do they tell you the awkward things unprompted?
How much this vendor volunteers before you have to ask.
Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.
The platform admin controls the formula's weights.
No buyer reviews yet.
No ratings in this window yet.
Self-hosted dev environment platform with AI agent governance via Terraform. AI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →
Certifications & compliance claimsWhat the tiers meanVerified in a public registry — we confirmed this against an authoritative public registry (FedRAMP Marketplace, CSA STAR) and re-check it by the registry's own identifier. Stated by the vendor — the vendor says it on a page they control; a sourced claim about themselves, not an independent check. Detected on a page — found during automated enrichment, neither registry-confirmed nor stated on the vendor's own site.
Some certifications have no public registry at all — SOC 2 and HIPAA among them. For those, “not registry-verified” is not a shortfall and means nothing about the vendor.
Detected on a page
Some of these (SOC 2, HIPAA and similar) have no public registry, so no one can independently verify them — that is a fact about the framework, not about this vendor.
Security headers (5/5) — checked 8/14/2026
The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors.
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
Product information on this page is auto-generated by 0-Doubt from public sources and not yet confirmed by the vendor or an independent analyst, unless an item is individually labelled otherwise. How trust works →
Are they still shipping, or coasting?
Whether this vendor is visibly still building.
Infrastructure & transparency signals
Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write…
The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bo…
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attack…
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or p…
WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state…