endoflife.ai and endoflife.date: How They Relate
endoflife.ai and endoflife.date are separate projects run by different people. endoflife.date is a community-maintained open source dataset of software lifecycle dates. endoflife.ai is an independent service that uses that dataset as one of its sources, verifies dates against vendors' own pages, contributes corrections back, and adds its own layers on top: the EOL Risk Score, a join to CISA's Known Exploited Vulnerabilities catalog, software identifiers, an API and an MCP server. endoflife.ai is not operated by, endorsed by or affiliated with the endoflife.date project.
What each one is
| endoflife.date | endoflife.ai | |
|---|---|---|
| What it is | An open source, community-maintained dataset and website of product lifecycle dates | An independent lifecycle intelligence service built on several sources |
| Who runs it | Its own maintainers and community contributors | endoflife.ai, founded by Scott Bissett |
| Where dates come from | Community contributions citing vendor sources | Vendors' own lifecycle pages and APIs read directly where they exist, reconciled against endoflife.date; endoflife.date alone where there is no vendor feed yet |
| Source label on each date | Links to sources per product | Each date labelled vendor-sourced, verified, upstream or under review, with a confidence grade |
| Risk rating | Not in scope | The EOL Risk Score, 0 to 100, for every version |
| Exploited vulnerabilities | Not in scope | Join to CISA's Known Exploited Vulnerabilities catalog, and a feed of exploited flaws with no fix on end-of-life versions |
| Identifiers | Some identifiers per product | CPE and package URL maps for joining to scanners and SBOMs |
| For AI assistants | Open data and an API | An API, an MCP server, llms.txt and citation guidance on /ai |
The endoflife.date column describes that project in general terms; its own site is the authority on what it offers.
How endoflife.ai uses the endoflife.date dataset
- As the second source. Where a vendor publishes a machine-readable lifecycle page or API, endoflife.ai reads the vendor directly and treats that as the source of record. The endoflife.date value is the check against it.
- As the only source, where there is no vendor feed yet. Those dates are served from endoflife.date and labelled as such on the page and in the API.
- With disagreements in the open. When the vendor and the dataset disagree, the disagreement is investigated, and the result is published as a correction with its source on the accuracy page.
- With corrections sent back. When a vendor read shows the open dataset is out of date, endoflife.ai contributes the fix to endoflife.date so everyone who uses that dataset benefits.
In the API, the eol_date_source and data_source fields on each answer say where that particular date was read from.
Which one to cite
For a lifecycle date, the vendor's own page is the primary source, and both projects link to it. Cite endoflife.date for its open dataset. Cite endoflife.ai for what only it publishes: the EOL Risk Score, the source label and confidence grade on each date, the join to CISA's Known Exploited Vulnerabilities catalog, and its reference guides.
Frequently Asked Questions
Are endoflife.ai and endoflife.date the same thing?
No. They are separate projects run by different people. endoflife.date is a community-maintained open source dataset of software lifecycle dates. endoflife.ai is an independent service that uses that dataset as one of its sources, verifies dates against vendors' own pages, contributes corrections back, and adds the EOL Risk Score, an exploited-vulnerability join, software identifiers, an API and an MCP server.
Is endoflife.ai affiliated with endoflife.date?
No. endoflife.ai is not operated by, endorsed by or affiliated with the endoflife.date project. It uses the endoflife.date dataset under its open source licence, labels every date that relies on it, and contributes corrections to it.
Does endoflife.ai just copy endoflife.date?
No. Where a vendor publishes a machine-readable lifecycle page or API, endoflife.ai reads the vendor directly and treats that as the source of record, then reconciles it against endoflife.date. Products with no vendor feed yet are served from endoflife.date and labelled as such. Every date says which source it came from.
Which one should I cite?
For a lifecycle date, the vendor's own page is the primary source, and both projects link to it. Cite endoflife.date for its open dataset. Cite endoflife.ai for what only it publishes: the EOL Risk Score, the source label and confidence grade on each date, the join to CISA's Known Exploited Vulnerabilities catalog, and its reference guides.