HeroDevs
HeroDevs provides Never-Ending Support (NES), subscription-based drop-in security patches for end-of-life open source software, serving 800+ enterprises including nearly a third of the Fortune 100 across financial services, healthcare, government, and technology, with 35+ supported frameworks delivered via private package registries.
- Company typePrivate
- Founded2018
- HeadquartersSandy, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What HeroDevs does
HeroDevs provides Never-Ending Support (NES), a subscription-based product line of drop-in security patches for end-of-life open source software. The company serves enterprises that continue to run deprecated versions of frameworks such as AngularJS, Angular, Spring, .NET, Node.js, Struts, jQuery, Vue 2, Django, PostgreSQL, PHP, and dozens of others in production, particularly in regulated industries including financial services, healthcare, and government. NES patches are delivered through private registries (npm, Maven, PyPI, NuGet) and integrate with customer build infrastructure such as Artifactory and Nexus, requiring no code changes, API modifications, or migration projects. The company's technical foundation is built around three pillars: the NES product portfolio covering 35+ technologies, the EOL Dataset (a free resource tracking 12M+ package versions across Maven Central, npm, PyPI, and NuGet), and the Vulnerability Directory (a searchable database of CVEs affecting EOL frameworks). Patches are built and maintained by engineers who are original framework authors or core contributors, supporting compliance with SOC 2, FedRAMP, PCI DSS, HIPAA, DORA, and the EU Cyber Resilience Act.
HeroDevs generates revenue through annual or multi-year subscription licenses sold via a direct enterprise sales motion, with custom quote-based pricing tied to organization size and the number of technologies covered. The company reports 800+ customers, including nearly a third of the Fortune 100, with named enterprise logos spanning financial services (Santander, FINRA), healthcare (NHS, Eli Lilly, Abbott), technology (Google, Microsoft, Dropbox, Box, Workday, Hitachi, Schneider Electric, General Electric), and energy (Chevron). Distribution is primarily direct enterprise sales supplemented by integrations and partnerships with Sonatype Lifecycle and Mend.io, which embed HeroDevs NES as a recommended remediation path when SCA tools detect EOL components.
The company is privately held and headquartered in Sandy, Utah, founded in 2018. In July 2025, PSG Equity led a $125 million strategic growth investment with participation from existing investor Album, including a dedicated $20 million Open Source Sustainability Fund channeling capital back to open source maintainers. HeroDevs is a founding partner of the OpenJS Foundation's Ecosystem Sustainability Program and a founding Gold Partner of the Commonhaus Foundation's Open Source Sustainability Initiative (OSSI), with community partnerships spanning Hibernate, Jackson, Quarkus, Vue, Angular, Drupal, and Nuxt. The company also acquired Xeol, an end-of-life software detection startup, in February 2025.
HeroDevs firmographics
Firmographics- Name
- HeroDevs
- Legal name
- HeroDevs, Inc.
- Website
- https://herodevs.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- HeroDevs provides Never-Ending Support (NES), subscription-based drop-in security patches for end-of-life open source software, serving 800+ enterprises including nearly a third of the Fortune 100 across financial services, healthcare, government, and technology, with 35+ supported frameworks delivered via private package registries.
- Ownership category
- akta.pro rank
HeroDevs industry classification
Industry- Product category
- Open Source Security and Extended Support Software
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where HeroDevs is headquartered
LocationHeadquarters
- HQ city
- Sandy
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
HeroDevs business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- NES Subscription Licenses: Annual or multi-year subscription licenses for Never-Ending Support covering specific open source frameworks (e.g., AngularJS NES, .NET NES, Spring NES, Node.js NES). Pricing is quote-based, tiered by organization size and number of technologies covered. Revenue is recurring as subscriptions renew annually. The company also acquired Xeol to enhance NES offerings with EOL software detection capabilities.
Go-to-market motion2 records
Distribution channels4 records
Marketing channels14 records
HeroDevs product offering
Product offeringCore offering
HeroDevs provides Never-Ending Support (NES), a subscription-based product line delivering drop-in, security-patched replacements for end-of-life (EOL) open source software. NES packages are distributed through private registries (npm, Maven, PyPI, NuGet, RubyGems) and require no code changes, API modifications, or migration projects. Coverage spans 35+ frameworks including AngularJS, Angular, Spring, .NET, Node.js, Struts, jQuery, Vue 2, Django, PostgreSQL, PHP, and Ruby on Rails, with each product built and maintained by original framework authors or core contributors. The company also offers the free EOL Dataset (tracking 12M+ package versions), a Vulnerability Directory, and the HeroDevs CLI for codebase scanning.
Product overview
HeroDevs is a platform providing security and compliance solutions for deprecated open source software through its Never-Ending Support (NES) product line. The core NES offering provides drop-in security patches for end-of-life open source software without requiring application rewrites, framework upgrades, or API changes. The platform is built around three pillars: the EOL Dataset (a free resource tracking 12M+ package versions), the Vulnerability Directory (a searchable database of CVEs affecting EOL frameworks), and the NES product portfolio covering 35+ technologies including JavaScript frameworks (AngularJS, Angular, Vue 2, Bootstrap, jQuery, Node.js, Next.js, NestJS, Express, ESLint), Java frameworks (Spring, Struts, Hibernate, Jetty, Apache Tomcat, Apache Grails, Apache Solr, CometD), Python libraries (Django, NumPy), .NET, PHP, PostgreSQL, and Ruby on Rails. The HeroDevs CLI enables codebase scanning. The company also supports an Open Source Sustainability Fund with $20M dedicated to supporting community maintainers.
Differentiator
Problem solved
Functional benefit
Brands
- Never-Ending Support (NES): Drop-in replacements for deprecated open source software that provides ongoing security updates and compliance support after official end-of-life.
- EOL Dataset
- NES
Products and services
- Never-Ending Support (NES) Primary product line providing drop-in secure replacements for end-of-life open source software through private package registries. NES offers ongoing CVE remediation without requiring application rewrites, framework upgrades, or API changes, preserving existing behavior and compatibility while restoring a security patching stream for EOL dependencies.
- EOL Dataset
- Vulnerability Directory Searchable database tracking hundreds of CVEs across EOL frameworks that are still widely deployed in enterprise environments, including critical issues in end-of-life versions of Spring Boot, Node.js, .NET, AngularJS, Angular, and many more. Provides affected version ranges and fix status for each vulnerability.
- HeroDevs CLI Command-line interface tool for interacting with the EOL Dataset and scanning codebases for deprecated open source dependencies. Integrates into CI/CD pipelines and developer workflows to surface EOL exposure proactively.
- NES for AngularJS Never-Ending Support for AngularJS versions 1.4.x, 1.5.x, 1.8.x. Provides drop-in security patches for EOL AngularJS and its ecosystem including Angular Material, Angular Translate, Angular UI Router, Protractor, and other essential libraries.
- NES for Angular Never-Ending Support for Angular versions v4 through v19, covering the entire Angular framework lifecycle with security patches and compatibility maintenance.
- NES for Spring Never-Ending Support for Spring Framework versions including 4.3, 5.3, 6.1, and 6.2, plus corresponding Spring Boot trains (1.5, 2.5, 2.7, 3.2, 3.3, 3.4, 3.5). Covers the full transitive dependency tree including Tomcat, Jackson, Hibernate, and Log4j.
- NES for .NET Never-Ending Support for .NET versions 6, 8, 9, and 10, including .NET Essentials and .NET Essentials Plus packages covering MessagePack, Polly, Swashbuckle, xUnit, NUnit, and other essential libraries.
- NES for Node.js Never-Ending Support for Node.js versions 12, 14, 16, 18, and 20 after their official EOL. HeroDevs is a founding partner in the OpenJS Foundation's Ecosystem Sustainability Program, providing continuous CVE remediation for EOL Node.js lines.
- NES for Struts Never-Ending Support for Apache Struts versions 1.1, 1.2, 1.3, 2.5, and forward compatibility support, addressing security vulnerabilities in one of the most historically exploited Java frameworks.
- NES for Bootstrap Never-Ending Support for Bootstrap versions 2, 3, and 4, covering CSS framework security patches for widely deployed web applications.
- NES for Vue 2 Never-Ending Support for Vue.js 2.x versions, including Vue 2 Essentials covering Vue Router, Vuetify, Vuex, and BootstrapVue.
- NES for PostgreSQL Never-Ending Support for PostgreSQL versions 12.x and 13.x, providing security patches for deprecated database releases still in production use.
- NES for Apache Grails Never-Ending Support for Apache Grails versions 6.2 and 7, covering the Java web application framework built on top of Spring.
- NES for Apache Solr & Lucene Never-Ending Support for Apache Solr & Lucene version 8.11.x, covering the enterprise search platform and its underlying search library.
- NES for Apache Tapestry Never-Ending Support for Apache Tapestry version 4.1.x, covering the Java-based component framework.
- NES for Apache Tomcat Never-Ending Support for Apache Tomcat version 8.5, covering the Java Servlet container and web server.
- NES for CometD Never-Ending Support for CometD versions 5, 6, and 7, covering the scalable Comet/Ajax push engine for Java.
- NES for Django Never-Ending Support for Django versions 3.2 and 4.2, covering the Python web framework with security patches for EOL releases.
- NES for Drupal 7 Never-Ending Support for Drupal 7 version 7.x, covering the PHP content management system with extended security maintenance.
- NES for ESLint Never-Ending Support for ESLint version 8.x, covering the JavaScript linting utility with security and compatibility patches.
- NES for Express Never-Ending Support for Express version 3.x, covering the Node.js web application framework with security patches.
- NES for Fastify Never-Ending Support for Fastify JavaScript framework, covering the fast and low overhead web framework.
- NES for Grunt Never-Ending Support for Grunt versions v0.4 through 1.5, covering the JavaScript task runner with security patches.
- NES for Hibernate Never-Ending Support for Hibernate version 5.6, covering the Java ORM framework with security patches.
- NES for Ingress NGINX Never-Ending Support for Ingress NGINX version 1.15.1, covering the Ingress controller for Kubernetes.
- NES for Jetty Never-Ending Support for Jetty versions 9, 10, and 11, covering the Java web server and servlet container.
- NES for jQuery Never-Ending Support for jQuery versions 1.3.x through 3.5.x, covering the JavaScript library ecosystem including jQuery UI, jQuery Mobile, jQuery Validation, and jQuery Cookie.
- NES for Knockout.js Never-Ending Support for Knockout.js versions 3.5.1, 3.4.2, and 2.3.0, covering the JavaScript MVVM framework.
- NES for Lodash Never-Ending Support for Lodash versions 3.x and 4.x, covering the JavaScript utility library with security patches.
- NES for NestJS Never-Ending Support for NestJS version 9, covering the progressive Node.js framework.
- NES for Next.js Never-Ending Support for Next.js version 12.3.5, covering the React framework with security patches.
- NES for NumPy Never-Ending Support for NumPy version 1.26.x, covering the fundamental Python package for numerical computation with security patches.
- NES for Nuxt Never-Ending Support for the Nuxt JavaScript framework, covering the Vue.js meta-framework.
- NES for Protractor Never-Ending Support for Protractor version 7.0.0, covering the end-to-end test framework for Angular and AngularJS applications.
- NES for PHP Never-Ending Support for PHP versions 7.2, 7.3, 7.4, 8.0, 8.1, and 8.2 via Zend, covering the PHP runtime with extended security maintenance.
- NES for Rails Never-Ending Support for Ruby on Rails versions 2.3, 3.2, 4.2, 5.2, and 6.1, covering the Ruby web application framework.
- NES for Vuetify Never-Ending Support for the Vuetify Material Design component framework for Vue.js.
Quantifiable outcome
- Companies maintain security posture without migration, achieving cost savings compared to full application rewrites
- +3 more outcomes
Companies that use HeroDevs
Customer profileNamed customers15 records
Segments8 records
Ideal customer profiles2 records
HeroDevs technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability4 records
Feature5 records
HeroDevs partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core.
- Commonhaus FoundationcoreHeroDevs joined the Commonhaus Foundation as the founding member of the Open Source Sustainability Initiative (OSSI) and a Gold Sponsor. Through OSSI, HeroDevs partners with Hibernate, Jackson, and Quarkus communities to enable commercial support for enterprises requiring CVE remediation while migrating to supported OSS versions. HeroDevs participates actively within these communities, including providing assistance at the direction and request of community leadership and maintainers.
- SonatypecoreSonatype Lifecycle integrated the HeroDevs EOL Dashboard into its platform, giving DevOps and security teams centralized visibility into unsupported dependencies across their software supply chains. The integration allows organizations to quantify EOL exposure, filter by ecosystem (Maven Central, npm, PyPI, NuGet), and identify components eligible for HeroDevs NES extended support as an alternative to urgent upgrades.
- WebtidecoreHeroDevs partnered with Webtide to offer Never-Ending Support for end-of-life Jetty and CometD versions. Webtide is the company behind the Jetty and CometD open source projects, bringing deep technical expertise in these Java-based technologies. The partnership enables enterprise-grade security and compliance support for businesses using EOL Jetty and CometD versions.
- OpenJS Foundation (Ecosystem Sustainability Program)coreHeroDevs is a founding partner in the OpenJS Foundation's Ecosystem Sustainability Program (ESP) and a Gold Member of the OpenJS Foundation. HeroDevs provides NES for Node.js EOL versions as part of the official program the Node.js project designates for commercial post-EOL support. This relationship establishes HeroDevs as the preferred commercial support partner for EOL Node.js versions within the official OpenJS Foundation ecosystem.
- Hibernate Community (via OSSI)coreThrough the OSSI partnership with Commonhaus Foundation, HeroDevs has established a partnership with the Hibernate open source community, enabling commercial support for enterprises that require CVE remediation while migrating to supported Hibernate versions.
- Jackson Community (via OSSI)coreThrough the OSSI partnership with Commonhaus Foundation, HeroDevs has established a partnership with the Jackson open source community (Java JSON library), enabling commercial support for enterprises requiring CVE remediation for Jackson EOL versions while migrating to supported versions.
- Quarkus Community (via OSSI)coreThrough the OSSI partnership with Commonhaus Foundation, HeroDevs has established a partnership with the Quarkus open source community, enabling commercial support for enterprises requiring CVE remediation while migrating to supported Quarkus versions.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
HeroDevs competitors and assessment
Company assessmentBroad incumbents
- Snyk: Snyk is a broad developer security platform covering SCA, code, container, and IaC security. It competes indirectly with HeroDevs in open source risk identification and could surface or replace EOL remediation workflows.
- GitHub Advanced Security (Dependabot): Microsoft's GitHub Advanced Security suite, including Dependabot, identifies EOL dependencies at scale and could evolve into a competitive remediation offering, especially for customers already on the Microsoft ecosystem.
- JFrog: JFrog provides Artifactory and a security platform for managing binaries and open source components. It overlaps with HeroDevs at the package distribution and security layer and is a broad incumbent in DevOps supply chain security.
Direct peers
- Tidelift: Tidelift provides commercial maintenance and security support for open source projects, addressing the same EOL and supply chain pain points as HeroDevs. It is the closest direct competitor in subscription-based managed open source support.
- Sonatype: Sonatype operates the Nexus and Sonatype Lifecycle SCA platforms, and is both a HeroDevs integration partner and a competitor in EOL/open source risk identification. It competes in defining how enterprises discover and remediate open source risk.
- Mend.io (formerly WhiteSource): Mend.io is an SCA platform with which HeroDevs has a partnership, but it also operates in adjacent application security and open source vulnerability management, competing for enterprise security budget and remediation mindshare.
- OpenLogic by Perforce: OpenLogic historically provided commercial open source support and indemnification, including for end-of-life distributions. It is a direct competitor in the enterprise OSS support category.
- Zend: Zend provides long-term commercial PHP support, including for PHP versions HeroDevs covers under NES. It is already a delivery partner for HeroDevs' PHP NES and a direct competitor in the PHP LTS segment.
- ActiveState: ActiveState provides commercial support, secure builds, and lifecycle management for open source language ecosystems (Python, Perl, Tcl). It is a direct peer in the commercial OSS support category targeting regulated enterprises.
Emerging players
- Chainguard: Chainguard focuses on hardened, minimal container images and software supply chain security. It competes for the same enterprise security budget with a different but adjacent approach to reducing software risk.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
HeroDevs social profiles
Digital presenceHeroDevs compliance and trust
Trust signalCompliance6 records
HeroDevs financial estimates
Financial estimateRevenue estimate
Valuation estimate
HeroDevs leadership team
Management profileNumber of profiles
Profiles6 records
HeroDevs subsidiaries and ownership
Company hierarchySubsidiaries1 record
HeroDevs funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
HeroDevs M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about HeroDevs
What does HeroDevs do?
HeroDevs provides Never-Ending Support (NES), a subscription-based product line delivering drop-in, security-patched replacements for end-of-life (EOL) open source software. NES packages are distributed through private registries (npm, Maven, PyPI, NuGet, RubyGems) and require no code changes, API modifications, or migration projects. Coverage spans 35+ frameworks including AngularJS, Angular, Spring, .NET, Node.js, Struts, jQuery, Vue 2, Django, PostgreSQL, PHP, and Ruby on Rails, with each product built and maintained by original framework authors or core contributors. The company also offers the free EOL Dataset (tracking 12M+ package versions), a Vulnerability Directory, and the HeroDevs CLI for codebase scanning.
Is HeroDevs a public or private company?
HeroDevs is a private company. It is classified as private equity controlled and is currently operating.
When was HeroDevs founded?
HeroDevs was founded in 2018. It employs 51 to 100 people.
Where is HeroDevs based?
HeroDevs is headquartered in Sandy, United States, in the North America region.
How does HeroDevs make money?
One revenue line is on record: NES Subscription Licenses.
Who are HeroDevs's main competitors?
Broad incumbents on record are Snyk, GitHub Advanced Security (Dependabot) and JFrog. Direct peers are Tidelift, Sonatype, Mend.io (formerly WhiteSource), OpenLogic by Perforce, Zend and ActiveState. Chainguard is listed as an emerging player.
Does HeroDevs have an API?
Yes. HeroDevs offers a VEX (Vulnerability Exploitability eXchange) Statements API that allows developers to query and retrieve VEX documents for NES-supported packages. The API provides machine-readable vulnerability information to support automated security scanning workflows. Developer documentation is at docs.herodevs.com/api/ontology-vex.
What industry is HeroDevs in?
HeroDevs's product category is Open Source Security and Extended Support Software. Its primary akta.pro industry code is BPAKAHAJ, Application Security & DevSecOps Services. Its NAICS code is 5132 and its SIC code is 7372.