Xeol
Y Combinator-backed platform that finds and remediates end-of-life, unmaintained open-source components that traditional vulnerability scanners miss.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Xeol builds tooling for application security teams to identify open-source software components that have reached end-of-life (EOL) or are no longer maintained by their upstream projects — a blind spot that conventional CVE-driven vulnerability scanners routinely miss, because an unmaintained package with no newly disclosed CVEs can look “clean” while actually being unpatched and unpatchable. The platform scans software supply chains, flags EOL and abandoned dependencies, and helps AppSec engineers prioritize and enforce remediation policy.
Founded in 2023 by ShiHan Wan and Benji Visser and launched out of Y Combinator’s Summer 2023 batch, Xeol positioned itself as a companion to existing SCA and vulnerability-management tools rather than a replacement, focusing narrowly on lifecycle status as a distinct risk signal. In February 2025, the company was acquired by HeroDevs, a firm that sells long-term “Never-Ending Support” for end-of-life open-source packages, and now operates as XEOL, a HeroDevs division — pairing Xeol’s detection capability with HeroDevs’ remediation and support business.
Innovation Matrix Assessment
Went from a 2023 YC launch to a working detection product and a strategic acquisition within about 18 months, though most evidence of iteration speed comes from the company's own launch materials.
Targets a genuine and underserved gap — unmaintained/EOL open-source dependencies that CVE-based scanners can under-flag — giving AppSec teams a new, actionable risk signal.
The clearest independent momentum signal is the 2025 acquisition by HeroDevs itself; no disclosed funding rounds or named enterprise customers were found.
Extends existing vulnerability-management and SCA workflows with an EOL-specific lens rather than replacing the category.
No independently published detection-rate data, audits, or customer case studies were found; efficacy claims rest on vendor and launch-page descriptions.
End-of-life and unmaintained open-source risk is a growing compliance and security concern as software supply chains lengthen, making the niche likely to stay relevant.
Why CISOs Should Care
Surfaces unmaintained and end-of-life open-source components in the software supply chain before they become unpatchable exposure, closing a gap standard CVE scanners leave open.
What Makes It Different
Treats software lifecycle status — not just disclosed CVEs — as a first-class vulnerability signal, and now pairs that detection with HeroDevs' long-term-support remediation service.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
Incremental Innovator. Xeol identified a real, narrow blind spot in vulnerability management and built a focused tool around it, validated by its 2025 acquisition into HeroDevs, but independent efficacy evidence and disclosed customer/funding metrics remain limited.
Editorial Note: Claims vs. Verified Findings
Detection-capability claims come from Xeol/HeroDevs materials; the acquisition itself is the strongest independently verifiable fact available.
Sources
Alternatives to Xeol
Unknown Cyber Inc.
CISO ReviewedMalware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…