Skip to content

Xeol

Y Combinator-backed platform that finds and remediates end-of-life, unmaintained open-source components that traditional vulnerability scanners miss.

Visit Website ↗ + Add to Compare Claim This Company
62/100Incremental Innovator

Overview

Xeol builds tooling for application security teams to identify open-source software components that have reached end-of-life (EOL) or are no longer maintained by their upstream projects — a blind spot that conventional CVE-driven vulnerability scanners routinely miss, because an unmaintained package with no newly disclosed CVEs can look “clean” while actually being unpatched and unpatchable. The platform scans software supply chains, flags EOL and abandoned dependencies, and helps AppSec engineers prioritize and enforce remediation policy.

Founded in 2023 by ShiHan Wan and Benji Visser and launched out of Y Combinator’s Summer 2023 batch, Xeol positioned itself as a companion to existing SCA and vulnerability-management tools rather than a replacement, focusing narrowly on lifecycle status as a distinct risk signal. In February 2025, the company was acquired by HeroDevs, a firm that sells long-term “Never-Ending Support” for end-of-life open-source packages, and now operates as XEOL, a HeroDevs division — pairing Xeol’s detection capability with HeroDevs’ remediation and support business.

Innovation Matrix Assessment

Innovation Velocity 7/10

Went from a 2023 YC launch to a working detection product and a strategic acquisition within about 18 months, though most evidence of iteration speed comes from the company's own launch materials.

Operational Value 7/10

Targets a genuine and underserved gap — unmaintained/EOL open-source dependencies that CVE-based scanners can under-flag — giving AppSec teams a new, actionable risk signal.

Market Momentum 6/10

The clearest independent momentum signal is the 2025 acquisition by HeroDevs itself; no disclosed funding rounds or named enterprise customers were found.

Category Disruption 5/10

Extends existing vulnerability-management and SCA workflows with an EOL-specific lens rather than replacing the category.

Real-World Efficacy 5/10

No independently published detection-rate data, audits, or customer case studies were found; efficacy claims rest on vendor and launch-page descriptions.

Enduring Relevance 7/10

End-of-life and unmaintained open-source risk is a growing compliance and security concern as software supply chains lengthen, making the niche likely to stay relevant.

Why CISOs Should Care

Surfaces unmaintained and end-of-life open-source components in the software supply chain before they become unpatchable exposure, closing a gap standard CVE scanners leave open.

What Makes It Different

Treats software lifecycle status — not just disclosed CVEs — as a first-class vulnerability signal, and now pairs that detection with HeroDevs' long-term-support remediation service.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

Incremental Innovator. Xeol identified a real, narrow blind spot in vulnerability management and built a focused tool around it, validated by its 2025 acquisition into HeroDevs, but independent efficacy evidence and disclosed customer/funding metrics remain limited.

Editorial Note: Claims vs. Verified Findings

Detection-capability claims come from Xeol/HeroDevs materials; the acquisition itself is the strongest independently verifiable fact available.

Sources