← Reference

End-of-life libraries

We report support status, not vulnerabilities. Here is why that distinction matters.

01

What we are telling you

That a library you ship no longer receives security patches from its maintainers. That is a checkable fact about the vendor, and it does not depend on us guessing your exact version from a minified bundle.

We deliberately do not claim "CVE-XXXX affects you". Doing that from a bundle would require version precision we cannot get, and a wrong CVE claim is the kind of false positive that ends a security product.

02

Why it still matters

End of life means the next issue found will never be fixed. Not that one exists today — that nobody is coming when one does.

It also compounds: every major version you fall behind makes the eventual upgrade larger, until it stops being a task and becomes a project.

03

How to approach the upgrade

One major version at a time, using the maintainer’s official upgrade guide or codemod. Ask your AI tool to tell you what will break and roughly how much work it is BEFORE it changes anything — that estimate is the useful part.

Not sure whether this applies to you?

Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.

Check a site