Built on the endoflife.date open dataset

End-of-life intelligence
for every major stack.

endoflife.ai is a free public platform for software end-of-life intelligence, built on top of the endoflife.date open dataset. Check whether a dependency is outdated, unsupported, or a security risk — instantly and for free.

Data sourced from endoflife.date, NVD, CISA KEV, and official vendor lifecycle pages. How we source data →

Check a Product → Browse All Products
455+
Products Indexed
8,400+
Pages & Score Cards
<7
Days to Exploit a New CVE
$0
Cost to Check
Trusted by security and engineering teams — free, no account required
455+
Products Tracked
7,500+
Score Card URLs
8,400+
Pages Indexed
$0
Cost Forever
Windows 10 — EOL Oct 2025 CentOS 7 — EOL Jun 2024 AngularJS — EOL Dec 2021 MySQL 5.7 — EOL Oct 2023 PHP 8.1 — EOL Dec 2025 Node.js 20 — EOL Apr 2026 MySQL 8.0 — EOL Apr 2026 Python 3.10 — EOL Oct 2026 PostgreSQL 14 — EOL Nov 2026 PHP 8.2 — EOL Dec 2026 Python 3.13 — Supported Node.js 22 LTS — Supported PostgreSQL 17 — Supported Ubuntu 24.04 LTS — Supported Kubernetes 1.33 — Supported Windows 10 — EOL Oct 2025 CentOS 7 — EOL Jun 2024 AngularJS — EOL Dec 2021 MySQL 5.7 — EOL Oct 2023 PHP 8.1 — EOL Dec 2025 Node.js 20 — EOL Apr 2026 MySQL 8.0 — EOL Apr 2026 Python 3.10 — EOL Oct 2026 PostgreSQL 14 — EOL Nov 2026 PHP 8.2 — EOL Dec 2026 Python 3.13 — Supported Node.js 22 LTS — Supported PostgreSQL 17 — Supported Ubuntu 24.04 LTS — Supported Kubernetes 1.33 — Supported
Free Tool

The EOL Checker

Instant lifecycle status for any software product. Paste in a product name and know your risk in seconds.

Product
Windows 10
EOL Date
Oct 14, 2025
Status
End of Life
CVE Blind Spot Detected. This product no longer receives security patches. Attackers diff new CVE fixes against your EOL build — your scanner won't alert you. They know. You don't.
Open Full EOL Checker — 455+ products →

Your scanner has a
blind spot.

CVE reporters only test supported software. When a vulnerability is discovered in code that also exists in your EOL version, they don't check — and neither does your scanner.

01
Incomplete CVE Reporting

Security researchers report vulnerabilities in supported versions only. EOL versions share the same vulnerable code but never appear in the advisory.

02
False Scanner Confidence

Your vulnerability scanner checks CVE affected version ranges. Your EOL version falls outside that range. No alert fires. You believe you're safe.

03
Attackers Know First

Threat actors read advisories and diff patches. They test EOL builds systematically. This isn't a zero-day — it's worse. They know. You don't.

Attack Chain — EOL Software
1
CVE Published
Vulnerability disclosed in supported versions only. Your EOL build has the same code.
2
Attacker reads the advisory
Diffs the patch. Tests against EOL builds. Confirms vulnerability present.
3
Your scanner runs
Checks CVE affected version range. EOL version not listed. No alert fires.
4
You believe you're clean
Dashboard shows green. Breach window is open.
endoflife.ai flags it first
EOL detected. CVE blind spot warning surfaced. Risk known before attacker acts.
Proprietary Intelligence

EOL Risk Score™

Every product and version page on endoflife.ai displays a proprietary 0–100 risk score — calculated at build time from four factors your vulnerability scanner doesn't track.

1
EOL Recency — 40 pts
How long past EOL — or how soon approaching. Accumulates over time with no reset.
2
Attack Surface — 30 pts
Critical tier for OS, runtimes, databases. High for frameworks and tools.
3
CISA KEV Exposure — 20 pts
Products with confirmed active exploitation history in the CISA KEV catalog.
4
Extended Support — 10 pts
No commercial patch vendor available means higher residual risk.
Full Methodology →
90
Critical
Node.js 16
EOL Sep 2023 · 2+ years past · CISA KEV · Critical tier
EOL
90
Critical
PHP 7.4
EOL Dec 2022 · 3+ years past · CISA KEV · Critical tier
EOL
85
Critical
Node.js 18
EOL Apr 2025 · 1 year past · CISA KEV · Critical tier
EOL
50
Medium
PHP 8.2
EOL Dec 2026 · 7 months away · Plan migration now
Warning
50
Medium
Node.js 22 LTS
EOL Apr 2027 · Currently active · High attack surface
Active
EOL Risk Score™ on all 8,400+ pages. Recalculated at every build. Methodology →
Resource Hub

Lifecycle Intelligence

Guides, timelines, and analysis for security and engineering teams managing software lifecycles.

⚠ Deadline — 17 Days
Debian 12 Bookworm EOL June 10, 2026 — What You Need to Do Now
What changes on June 10, who is at risk, Docker base image checklist, compliance implications, and your step-by-step upgrade path to Debian 13 before the deadline.
endoflife.ai Research · May 2026 · 7 minRead →
Live Tool · CISA KEV
CVE Intelligence — EOL Software with Active CISA KEV Exposure
Every product in the CISA Known Exploited Vulnerabilities catalog cross-referenced against EOL status. Live Risk Scores, sortable by urgency. The CVE blind spot made visible.
endoflife.ai · Live data · Updated at page loadExplore →
EOL — April 30, 2025
Node.js 18 End of Life: Which Vendors Offer Extended Security Support?
Node.js 18 is end of life. No patches since April 2025. Compare extended lifecycle support vendors extended lifecycle support options — CVE coverage, compliance docs, and contract terms.
endoflife.ai Research · May 2026 · 5 minRead →
EOL — Dec 31, 2026
PHP 8.2 End of Life: December 31, 2026 — Migration Guide & Extended Support
PHP 8.2 is in security-only support with 220 days until EOL. See the exact date, upgrade path to PHP 8.3, live countdown, and which vendors cover PHP 8.2 after end of life.
endoflife.ai Research · May 2026 · 6 minRead →
Ubuntu 20.04 EOL
Ubuntu End of Life Dates 2026 — Which Vendors Offer Extended Security Support?
Ubuntu 20.04 is already EOL. Ubuntu 22.04 reaches end of standard support April 2027. Full EOL date table and vendor comparison: Canonical ESM, TuxCare ELS, enterprise support vendors.
endoflife.ai Research · May 2026 · 6 minRead →
Operating System
Debian EOL Dates — Official Lifecycle Schedule for Every Version
Debian 12 regular support ends June 10, 2026. Debian 11 LTS ends June 30. All three support phases — regular, LTS, and ELTS — explained with EOL Risk Scores and migration guidance for every version.
endoflife.ai Research · May 2026 · 8 minRead →
Operating System
RHEL End-of-Life Dates — Official EOL Schedule for Every Version
RHEL 7 fully EOL since June 2024. RHEL 8 in Maintenance Support until 2029. Full Support, Maintenance, Extended Life, and ELS phases explained with EOL Risk Scores.
endoflife.ai Research · May 2026 · 9 minRead →
Framework
Django End-of-Life Dates — Official EOL Schedule for Every Version
Django 4.2 LTS reached EOL April 7, 2026. LTS vs standard releases explained, Python compatibility matrix, EOL Risk Scores, and a step-by-step upgrade guide.
endoflife.ai Research · May 2026 · 8 minRead →
Database
MariaDB End-of-Life Dates — Official EOL Schedule for Every Version
MariaDB 10.6 LTS reaches EOL July 6, 2026. LTS vs rolling releases explained, EOL Risk Scores, and a step-by-step upgrade guide.
endoflife.ai Research · May 2026 · 8 minRead →
Framework
React End-of-Life Dates — What's Actually Supported in 2026
Meta doesn't publish hard React EOL dates. React 18 is security-only. React 17 and 16 are unsupported. Here's what that means and how to upgrade.
endoflife.ai Research · May 2026 · 7 minRead →
Infrastructure
Kubernetes End-of-Life Dates — Official EOL Schedule for Every Version
K8s 1.32 is EOL. K8s 1.33 reaches end of life June 28, 2026. Official dates, EOL Risk Scores, EKS/GKE/AKS support windows, and a step-by-step upgrade guide.
endoflife.ai Research · May 2026 · 9 minRead →
Compliance
Hidden Compliance Risks from Unsupported Software
SOC 2, PCI DSS, HIPAA, and ISO 27001 all share one quiet vulnerability: unsupported software. Here's what your auditors will find — before you do.
endoflife.ai Research · May 2026 · 8 minRead →
Compliance
Your EOL Dependencies Are a Compliance Problem — Not Just Tech Debt
That outdated Node or Python version isn't just a "we should upgrade someday" item. If your company is going through SOC 2, PCI, or HIPAA, it's a finding waiting to happen.
endoflife.ai Research · May 2026 · 7 minRead →
Runtime
PHP End-of-Life Dates — Official EOL Schedule for Every Version
PHP 7.4, 8.0, and 8.1 are all currently EOL. PHP powers 77% of the web — making EOL PHP one of the most widespread security risks in the ecosystem. Official dates, scores, and migration guidance.
endoflife.ai Research · May 2026 · 8 minRead →
Framework
Spring Framework End-of-Life Dates — Official EOL Schedule for Every Version
Spring 5.3, 6.0, and 6.1 are all currently EOL. Three major versions unpatched simultaneously. Official dates, EOL Risk Scores, and migration guidance for every version.
endoflife.ai Research · May 2026 · 8 minRead →
Security
The Security Blind Spot Nobody Is Talking About Enough
EOL software gets a clean bill of health from every CVE scanner. Here's why that's the most dangerous gap in enterprise security — and what we built to close it.
Scott Bissett · May 2026 · 10 minRead →
Runtime
Node.js End-of-Life Dates — Official EOL Schedule for Every Version
Node.js 14, 16, 18, and 20 are all EOL. Official dates, EOL Risk Scores, breaking changes, and a 5-step migration guide for every version.
endoflife.ai Research · May 2026 · 8 minRead →
Runtime
Python End-of-Life Dates — Official EOL Schedule for Every Version
Python 3.10 and 3.11 both reach EOL on October 31, 2026. Official dates, EOL Risk Scores, and migration guidance for every Python version.
endoflife.ai Research · May 2026 · 8 minRead →
Risk Intelligence
The EOL Risk Score: Why CISOs and DevOps Teams Are Measuring Software Risk Wrong
Your vulnerability scanner gives EOL packages a clean bill of health. That silence is not safety — it is a measurement failure. Here is the metric that fills the gap.
endoflife.ai Research · May 2026 · 8 minRead →
2026 EOL Report
The Top 50 Products Reaching End of Life in 2026
The definitive list — 50 products, exact dates, CVE risk ratings, and migration guidance. Updated quarterly.
endoflife.ai Research · May 2026 · 12 minRead →
Security
The CVE Blind Spot: Why EOL Software Is More Dangerous Than a Zero-Day
With a zero-day, nobody knows. With EOL software, the attacker knows and you don't. Here's why that asymmetry is the most dangerous gap in enterprise security.
endoflife.ai Research · May 2026 · 8 minRead →
IT Security
Windows 10 End of Life: The Complete Migration Guide for IT Teams
Windows 10 reached EOL October 14, 2025. Millions of enterprise machines are running unpatched. Here is what you need to do now.
endoflife.ai Research · Apr 2026 · 9 minRead →
Open Source
The 2026 EOL Calendar: Every Major Runtime and Framework
Python, Node.js, PHP, Ruby, Java LTS — every major platform support window in one place, updated quarterly.
endoflife.ai Research · May 2026 · 5 minRead →
Enterprise
The Hidden Cost of Running EOL Software: A CISO's Risk Framework
Unsupported software is not just technical debt. It is a material security risk. Here is how to quantify it and present it to your board.
endoflife.ai Research · May 2026 · 10 minRead →
Hardware
EOSL for Enterprise Hardware: Cisco, HPE, Dell EMC Timelines
When your storage arrays and network gear hit end-of-service-life, the security clock starts. A vendor-by-vendor breakdown of critical dates.
endoflife.ai Research · Apr 2026 · 7 minRead →
Compliance
Why Your EOL Risk Score Is the Most Important Number in Your Security Stack
What the EOL Risk Score™ measures, how it maps to SOC 2, ISO 27001, and PCI DSS, and the real-world consequences — Equifax, MOVEit, Log4Shell — of ignoring it.
endoflife.ai Research · May 2026 · 14 minRead →
Developer API — Live
Integrate EOL intelligence into your stack
Query lifecycle data programmatically. Built for CI/CD pipelines, SBOMs, security scanners, and dependency tooling. Free tier available.
Get API Key →
Free · Pro $199/mo · Enterprise custom
¹ Source: Verizon Data Breach Investigations Report (DBIR) — vulnerability exploitation data based on confirmed breach analysis.