Back to Browse

Endoflife MCP Server

Developer ToolsModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

EOL dates and risk scores for 480+ software products. Check versions, score risk, audit stacks.

About

EOL dates and risk scores for 480+ software products. Check versions, score risk, audit stacks.

Remote endpoints: streamable-http: https://mcp.endoflife.ai

Security Report

6.2
Moderate6.2Moderate Risk

Well-designed MCP server with clean architecture and appropriate security practices. The server properly forwards optional API keys without storing credentials, implements correct CORS headers, and has no dangerous patterns. Minor code quality concerns around input validation and error handling do not materially impact security. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 2 high severity).

3 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

endoflife.ai — MCP Server

Node.js EOL status EOL data: endoflife.ai

Exposes endoflife.ai's lifecycle intelligence to AI agents over the Model Context Protocol (MCP, Streamable HTTP transport). It's a thin, dependency-free Cloudflare Worker that wraps the existing api.endoflife.ai/v1 endpoints — no data duplicated.

Tools

ToolWhat it doesWraps
check_eolIs product X version Y end-of-life?GET /v1/status/:slug/:version
get_risk_scoreEOL Risk Score™ (0–100) + factor breakdownGET /v1/score/:slug[/:version]
scan_stackScore a whole stack at oncePOST /v1/batch
list_productsSearch the 480+ tracked products → resolve slugsGET /v1/products
get_product_lifecycleFull version history + dates for one productGET /v1/product/:slug

Deploy

Prereq: npm install -g wrangler and wrangler login (once).

cd mcp-server
npm install
# Test immediately on the workers.dev URL:
wrangler deploy          # prints https://endoflife-mcp.<your-subdomain>.workers.dev
# Production (custom domain):
wrangler deploy --env production

Custom domain (mcp.endoflife.ai)

The route in wrangler.toml needs mcp.endoflife.ai to resolve through Cloudflare:

  1. Cloudflare dashboard → endoflife.ai zone → DNSAdd record.
  2. Type AAAA, Name mcp, IPv6 100::, Proxied (orange cloud). (This is the standard Cloudflare placeholder for a Worker route — the Worker intercepts before the address is ever used.)
  3. Re-run wrangler deploy --env production.

Until DNS is set, use the workers.dev URL everywhere below.

Connect from an MCP client

Claude Desktop / Cursor (claude_desktop_config.jsonmcpServers):

{
  "mcpServers": {
    "endoflife": { "command": "npx", "args": ["mcp-remote", "https://mcp.endoflife.ai"] }
  }
}

Clients with native remote-MCP support can use the URL directly:

{ "mcpServers": { "endoflife": { "url": "https://mcp.endoflife.ai" } } }

Test without a client

# tools/list
curl -s https://mcp.endoflife.ai -X POST -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | jq

# call a tool
curl -s https://mcp.endoflife.ai -X POST -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_risk_score","arguments":{"product":"openssl"}}}' | jq

# discovery card
curl -s https://mcp.endoflife.ai/.well-known/mcp/server-card.json | jq

Auth & tiers

Free tier works with no key. Forward an X-API-Key header (your existing Pro keys) to unlock Pro limits — the Worker passes it straight through to api.endoflife.ai.

Notes / Phase 2

  • Per-client rate limits: Phase 1 relies on the upstream API's limits. If MCP traffic grows, add a KV rate-limiter here keyed on CF-Connecting-IP (reuse the API_RATE_LIMIT namespace) before the upstream call.
  • Registry listings: submit to the public MCP registries once live (see the launch checklist).
  • Discovery card is also served from the main site at https://endoflife.ai/.well-known/mcp/server-card.json so agents that probe the apex domain find it.

Reviews

No reviews yet

Be the first to review this server!

Endoflife MCP Server - EOL dates and risk scores for 480+ software products. Check | MCP Marketplace