End-of-life libraries
We report support status, not vulnerabilities. Here is why that distinction matters.
What we are telling you
That a library you ship no longer receives security patches from its maintainers. That is a checkable fact about the vendor, and it does not depend on us guessing your exact version from a minified bundle.
We deliberately do not claim "CVE-XXXX affects you". Doing that from a bundle would require version precision we cannot get, and a wrong CVE claim is the kind of false positive that ends a security product.
Why it still matters
End of life means the next issue found will never be fixed. Not that one exists today — that nobody is coming when one does.
It also compounds: every major version you fall behind makes the eventual upgrade larger, until it stops being a task and becomes a project.
How to approach the upgrade
One major version at a time, using the maintainer’s official upgrade guide or codemod. Ask your AI tool to tell you what will break and roughly how much work it is BEFORE it changes anything — that estimate is the useful part.
Not sure whether this applies to you?
Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.
Check a site