Why we built this
A CVE-based scan tells you about known flaws — it does not tell you that a runtime has passed end of life. When Node.js 18 went end-of-life in April 2025, every new CVE disclosed after that date accumulated with no vendor patch path. Some scanners flag unsupported versions of common products, but coverage varies, and none of them warn you in advance. Teams stayed exposed.
That's the CVE blind spot. With a zero-day, nobody knows the vulnerability exists. With EOL software, the vulnerability is public — listed on NVD, rated by CVSS, often with exploit code on GitHub — but no vendor patch is coming. A scan can still come back clean. Attackers know exactly what's there.
endoflife.ai was built to close that gap. We track every major product's lifecycle, quantify the risk with our proprietary EOL Risk Score™, and make the data freely available to every developer, security team, and platform that needs it.
Builder, entrepreneur, and infrastructure obsessive based in Calgary, Alberta, Canada. Built endoflife.ai to give security and engineering teams the one reference they need for software lifecycle intelligence — free, comprehensive, and always current.