Skip to main content
MCP Servers / endoflife.ai - Software Lifecycle Intelligence

endoflife.ai - Software Lifecycle Intelligence

End-of-life dates, EOL Risk Scores, CISA KEV exposure, SBOM audits and edge-device end-of-support status for 500+ products, read-only, no key required.

Transportboth
Runtimenode
LicenseMIT
AddedSep 14, 2026
ReviewedSep 16, 2026

Baseline review at submission: an accuracy and overt-behavior check, not a full security audit, and it does not cover later changes to the repository. Learn more about our security review process.

Compatible Clients

Claude CodeClaude DesktopCursorVS Code CopilotWindsurfClineGemini CLICodex

Integrations

Tools (10)

  1. check_eol

    Is product X version Y past end of life? Status, dates and the source the date was read from.

  2. get_risk_score

    EOL Risk Score (0-100) with the factor breakdown: recency, attack surface, CISA KEV exposure, extended support.

  3. scan_stack

    Score a whole stack of product/version pairs in one call.

  4. list_products

    Search the 500+ tracked products and resolve names to slugs.

  5. get_product_lifecycle

    Full version history and lifecycle dates for one product.

  6. get_kev_exposure

    Every CISA Known Exploited Vulnerabilities entry attributed to a product, with due dates and required action, plus the exploited-and-unpatchable entries.

  7. get_upcoming_eol

    Everything reaching end of life in the next N days, catalog-wide or for a product list.

  8. get_edge_device_status

    End-of-support status for network edge platforms (firewalls, VPN gateways, routers, load balancers) against CISA BOD 26-02.

  9. get_upgrade_path

    Supported upgrade targets and the vendor-stated successor for a version.

  10. check_sbom

    CycloneDX or SPDX in; every component resolved by package URL and scored; unmatched components listed with a reason, never guessed.

Resources (7)

  1. https://endoflife.ai/llms.txt

    endoflife.ai guide for assistants: what the site publishes, how to cite it, and the article index.

  2. https://endoflife.ai/eos-edge-devices.json

    EOS Edge Device Intelligence feed: edge platforms with BOD 26-02 end-of-support statuses, KEV records, CPEs and provenance.

  3. https://endoflife.ai/exploited-and-unpatchable.json

    Exploited & Unpatchable feed: exploited CVEs whose affected versions will never receive a fix.

  4. https://endoflife.ai/verification.json

    Accuracy and provenance report: where every served date comes from, live vendor feeds, open disagreements and published corrections.

  5. https://endoflife.ai/purl-map.json

    Package URL map: the purl-to-product join key that check_sbom uses.

  6. https://endoflife.ai/kev-products.json

    CISA KEV by product: every tracked product with its attributed KEV entries, dates, due dates and required actions.

  7. https://endoflife.ai/eos-edge-changelog.json

    EOS Edge feed change log: every edge line added, removed, re-dated or status-changed, by build date.

Prompts (3)

  1. audit_stack

    Score every component of a stack, then explain what is end-of-life, what is actively exploited, and where to move.

  2. eol_calendar

    List what reaches end-of-life in a window, grouped by month, with the action each one needs.

  3. edge_device_review

    Review edge devices against CISA BOD 26-02: past end of support, within 12 months, and the KEV exposure of each.

Tags

end-of-lifeeolend-of-supportsoftware-lifecyclecisa-kevrisk-scoresbomedge-devicesbod-26-02exposure-managementnode

Vulnerability scanners find the CVEs you have. This server answers the question underneath: is the software still receiving fixes at all, and if not, how urgent is that?

What it does

endoflife.ai keeps lifecycle dates for 500+ products (operating systems, runtimes, databases, frameworks, network appliances and AI models), reconciled against the vendors’ own lifecycle pages and the endoflife.date community dataset, with the source returned on every answer. The MCP server exposes that data read-only, with no key required:

  • Status and dates for a product version, and the full lifecycle of a product.
  • EOL Risk Score, 0 to 100, from how long a version has been unpatched, its attack surface, whether CISA lists it as actively exploited, and whether extended support can still be bought. The methodology is public at endoflife.ai/risk-score.
  • CISA KEV join: which exploited vulnerabilities attach to a product, and the exploited-and-unpatchable set, meaning past end of life and on the KEV list, where no fix is coming.
  • Forward calendar: what crosses end of life in the next 30, 90 or 365 days, so a team plans instead of reacts.
  • SBOM audit: CycloneDX or SPDX in, components resolved by package URL, scored, and unmatched components named rather than guessed.
  • Edge devices: 54 network appliance platforms (1,600+ release lines) against the BOD 26-02 deadline.

How it works

The server is a thin, stateless layer over the public endoflife.ai API and its published JSON feeds. It runs hosted at mcp.endoflife.ai (streamable HTTP) or locally with npx endoflife-mcp (stdio); a Red Hat UBI container image is included for cluster deploys. Every tool is read-only and every answer carries eol_date_source, the vendor page or upstream record the date was read from. Lookup misses return “did you mean” suggestions instead of a guess.

Where it fits with Tenable

Tenable’s Security End of Life plugins tell you which scanned assets already run software past its security EOL. This server adds what a plugin cannot: the dates ahead (what goes out of support next quarter), the source behind each date, a severity that ranks EOL findings against each other, the CISA KEV cross-reference, whether paid extended support exists, and edge-device lines that a network scan sees only as a firmware string. Two listings already on this exchange (Tenable Asset EOL Tracker and security-intel-brief) pull lifecycle data from endoflife.date; this server is the same idea as a callable MCP layer, with vendor-verified corrections applied and the Risk Score and KEV join on top.

Typical agent use: pull an asset or package inventory from Tenable VM or a CMDB, call scan_stack or check_sbom, then get_kev_exposure for anything past end of life, and rank by EOL Risk Score. get_upcoming_eol turns the same inventory into a 90-day plan.

Prerequisites and limits

  • Hosted endpoint needs only outbound HTTPS; the stdio server runs on a current Node.js (the container image ships Node 22).
  • No authentication and no write operations; nothing is stored between calls.
  • Coverage is 500+ products; a product not in the catalog returns “not tracked” with suggestions, never a guessed date.
  • Not yet tested against Tenable Hexa AI’s MCP support, so works_with_tenable_hexa_mcp is false until it is.