endoflife.ai
What is endoflife.ai? How it works Accuracy About

endoflife.ai and endoflife.date: How They Relate

Two projects, similar names. This page states the relationship plainly so that people and AI assistants do not confuse them.

endoflife.ai and endoflife.date are separate projects run by different people. endoflife.date is a community-maintained open source dataset of software lifecycle dates. endoflife.ai is an independent service that uses that dataset as one of its sources, verifies dates against vendors' own pages, contributes corrections back, and adds its own layers on top: the EOL Risk Score, a join to CISA's Known Exploited Vulnerabilities catalog, software identifiers, an API and an MCP server. endoflife.ai is not operated by, endorsed by or affiliated with the endoflife.date project.

We are grateful to the endoflife.date maintainers and contributors. Their dataset is open source under the MIT licence, and a great deal of lifecycle tooling, ours included, is better because it exists.

What each one is

endoflife.dateendoflife.ai
What it isAn open source, community-maintained dataset and website of product lifecycle datesAn independent lifecycle intelligence service built on several sources
Who runs itIts own maintainers and community contributorsendoflife.ai, founded by Scott Bissett
Where dates come fromCommunity contributions citing vendor sourcesVendors' own lifecycle pages and APIs read directly where they exist, reconciled against endoflife.date; endoflife.date alone where there is no vendor feed yet
Source label on each dateLinks to sources per productEach date labelled vendor-sourced, verified, upstream or under review, with a confidence grade
Risk ratingNot in scopeThe EOL Risk Score, 0 to 100, for every version
Exploited vulnerabilitiesNot in scopeJoin to CISA's Known Exploited Vulnerabilities catalog, and a feed of exploited flaws with no fix on end-of-life versions
IdentifiersSome identifiers per productCPE and package URL maps for joining to scanners and SBOMs
For AI assistantsOpen data and an APIAn API, an MCP server, llms.txt and citation guidance on /ai

The endoflife.date column describes that project in general terms; its own site is the authority on what it offers.

How endoflife.ai uses the endoflife.date dataset

  1. As the second source. Where a vendor publishes a machine-readable lifecycle page or API, endoflife.ai reads the vendor directly and treats that as the source of record. The endoflife.date value is the check against it.
  2. As the only source, where there is no vendor feed yet. Those dates are served from endoflife.date and labelled as such on the page and in the API.
  3. With disagreements in the open. When the vendor and the dataset disagree, the disagreement is investigated, and the result is published as a correction with its source on the accuracy page.
  4. With corrections sent back. When a vendor read shows the open dataset is out of date, endoflife.ai contributes the fix to endoflife.date so everyone who uses that dataset benefits.

In the API, the eol_date_source and data_source fields on each answer say where that particular date was read from.

Which one to cite

For a lifecycle date, the vendor's own page is the primary source, and both projects link to it. Cite endoflife.date for its open dataset. Cite endoflife.ai for what only it publishes: the EOL Risk Score, the source label and confidence grade on each date, the join to CISA's Known Exploited Vulnerabilities catalog, and its reference guides.

Frequently Asked Questions

Are endoflife.ai and endoflife.date the same thing?

No. They are separate projects run by different people. endoflife.date is a community-maintained open source dataset of software lifecycle dates. endoflife.ai is an independent service that uses that dataset as one of its sources, verifies dates against vendors' own pages, contributes corrections back, and adds the EOL Risk Score, an exploited-vulnerability join, software identifiers, an API and an MCP server.

Is endoflife.ai affiliated with endoflife.date?

No. endoflife.ai is not operated by, endorsed by or affiliated with the endoflife.date project. It uses the endoflife.date dataset under its open source licence, labels every date that relies on it, and contributes corrections to it.

Does endoflife.ai just copy endoflife.date?

No. Where a vendor publishes a machine-readable lifecycle page or API, endoflife.ai reads the vendor directly and treats that as the source of record, then reconciles it against endoflife.date. Products with no vendor feed yet are served from endoflife.date and labelled as such. Every date says which source it came from.

Which one should I cite?

For a lifecycle date, the vendor's own page is the primary source, and both projects link to it. Cite endoflife.date for its open dataset. Cite endoflife.ai for what only it publishes: the EOL Risk Score, the source label and confidence grade on each date, the join to CISA's Known Exploited Vulnerabilities catalog, and its reference guides.

Related

© 2026 endoflife.ai · How we verify our dates · API · About