End of life software: what the dates mean, and how to check a product still exists

End of life software is a product the vendor has stopped developing, stopped patching and stopped selling. End of support is the earlier moment when official support stops while the code keeps running. Microsoft publishes both dates years ahead of time. Most SaaS vendors publish neither, and I ran a test to find out what a buyer gets when they ask anyway. This report is for the person deciding if a tool already in the stack is safe to renew. It covers what the two terms mean, what the security and compliance exposure costs with current figures, how three vendors describe their own dead or renamed software products, and the checks that settle the question in under a minute. Renewing a product that stopped being maintained is a bill you pay for nothing.

The numbers Software lifecycle, checked 9 August 2026

301Response from hotjar.com/pricinghotjar.com
$4.99MAverage cost of a data breachIBM, 2026
$61Windows 10 ESU, per device, year oneMicrosoft
$30Consumer ESU through Oct 2027Microsoft
2 of 2AI engines that missed the redirectDataForSEO probe
16Vendor self-contradictions loggedOwn audit
33"acquired and killed" posts, 2012-2026Hacker News

A SaaS product's death shows up in an HTTP status code before it shows up in prose.

Both engines asked if Hotjar still exists said yes, and neither read the 301.

Microsoft prices three years past end of support. SaaS vendors publish no date to price against.

Read the response code on the pricing URL before you approve the renewal.

End of life EOL and end of support EOS: what each term means

Microsoft's lifecycle definitions page draws the line in one sentence: end of support is "the end of Extended Support for products governed by the Fixed Policy, when support and servicing will no longer be available." For services on its Modern Policy, the word is retirement, "the end of availability and support of the service."

EOS software still runs. What ends is technical support and security updates. End of life (EOL) is the complete cessation of development, sale and vendor support, and the product is considered obsolete from that point. Deprecation sits earlier than both lifecycle stages: the feature still works and still ships, and the vendor has told you to stop building on it.

The order varies. On hardware, EOL usually lands first and EOS trails it by years while replacement parts and firmware updates stay available. On software, EOL often follows EOS, and the two dates can be the same day. Neither has anything to do with useful life, which is the accounting question of how long the asset gets depreciated.

How Microsoft publishes a lifecycle, and what extended support costs

Microsoft named the Windows 10 date more than three years out. Version 22H2 was declared the final version, and the lifecycle table carries a retirement timestamp of 15 October 2025, 06:59:59 Pacific, which is the close of 14 October 2025.

What stops is spelled out on support.microsoft.com: "After October 14, 2025, computers running Windows 10 will still function, but Microsoft will no longer provide the following: Technical support of any issue; Software updates; Security updates or fixes." The machine boots. Nothing behind it moves.

Two lifecycle tracks: Windows 10 with a named 22H2 final version, a 14 October 2025 retirement date, and three ESU years starting at $61 doubling each year, against Hotjar with an acquisition, a 301 redirect, and no published dates at all
Microsoft names a retirement date and prices the years past it. Hotjar's lower track has nothing to publish.

Extended support exists and it has a price. Consumers enrol through 12 October 2027 for a one-time $30, or 1,000 Microsoft Rewards points, or free if PC settings are syncing; one licence covers up to 10 devices and includes no technical support. Organisations buy through Volume Licensing at $61 per device for Year One, and Microsoft states the price "doubles every consecutive year, for a maximum of three years." Purchases are cumulative, so an IT environment that skips Year One and buys in Year Two pays for both.

That is a lifecycle a buyer can plan against: a named supported version, published EOS dates, a costed bridge, and vendor announcements years ahead. Hold it next to what SaaS publishes.

Why SaaS products never get an end of life date

Hotjar has no EOL date and no EOS date, and it is no longer a product a new buyer can purchase. Request hotjar.com/pricing and the server answers 301, redirecting to contentsquare.com/pricing, Contentsquare's own page. Existing accounts still work; help.hotjar.com documents Hotjar Free as live. The product died in an HTTP status code.

Hotjar also publishes two plan vocabularies for itself. The pricing page sells Free, Growth, Pro and Enterprise. The help centre documents Basic, Plus, Business and Scale, and gates the API to Scale. Both sets are current & both are Hotjar's own.

The same pattern runs across the category. Conductor acquired Searchmetrics and wound the platform down, which is documented on our Searchmetrics report. Surfer has never been called Surfer SEO, that name came off the domain, and since October 2025 the product has been Positive Surfer. Every review blog still runs the old name.

Buyers have been complaining about this for fifteen years. The phrase "acquired and killed" returns 33 Hacker News hits spanning 2012 to May 2026. Writing on 23 December 2023, the user ljm listed two in a row:

Remember Sparrow? (acquired and killed by Google, turned into Inbox then killed again) / Remember Mailbox? (acquired and killed by Dropbox)

killedbygoogle.com has been submitted to the same site at least eight times, and the four biggest threads carry 99, 60, 58 and 43 comments.

What AI search returns when you ask if a product still exists

I put the Hotjar question to two engines on 9 August 2026 through the DataForSEO AI Optimization API with web search on. The verified answer is that Hotjar Free works for existing accounts and a new buyer gets routed to Contentsquare.

EngineModelAnswerSources cited
ChatGPTgpt-5.4-2026-03-05Still active, "now part of Contentsquare", some new users "may be steered toward that broader offering"1, help.hotjar.com
Perplexitysonar-pro"still available", status page shows it "operational, not discontinued"15 domains, 6 of them uptime monitors
ChatGPT and Perplexity both told to ask if Hotjar still exists, both answered yes, one citing one source and the other citing fifteen, neither reporting the 301 redirect
Neither engine reads a status code. Both engines answer the availability question with citations to product-review sites and uptime monitors instead.

Neither answer mentions the 301. Perplexity established that a product can still be bought by citing statussight.com, servicealert.ai, isdown.app, statusgator.com, pagerly.io and a Hindi-language entireweb page. Server uptime and commercial availability are different questions. Nothing in an answer pipeline reads status codes.

The second probe was sharper. Asked if Sprout Social has a public API, both engines said yes and both were right. ChatGPT's visible reasoning trace records what it did with the conflict:

There seems to be a contradiction: the FAQ states there's no public API available right now, while the support documentation suggests that a public API could be part of an add-on or Advanced plan.

It resolved the contradiction correctly and returned a clean yes. The buyer never learns the vendor publishes both answers. Contradiction detection is happening. Disclosure is not.

Vendors publishing two answers about their own products

Sixteen of these are logged across our compare pages. Four bear on product identity rather than pricing.

VendorClaim AClaim B
Sprout SocialFAQ states there is no public APIapi.sproutsocial.com documents one with published rate limits
CognismNames ZoomInfo's products as SalesOS, MarketingOS, TalentOSZoomInfo's navigation sells Copilot, GTM Workspace, GTM Studio
6senseDescribes Chorus as an advertising capability, "now ZoomInfo Copilot"Chorus is conversation intelligence and is a separate product
AmplitudePricing page sells Heatmaps as a Plus featureHeatmaps documentation requires the Session Replay add-on, sold from Growth

Two of those four involve Cognism mischaracterizing a competitor's product line. Cognism's page still names ZoomInfo's products as SalesOS, MarketingOS and TalentOS, and 6sense makes the same kind of stale claim about its own Chorus product, both from pages that stopped being updated.

The other two involve a vendor contradicting its own documentation. Sprout Social's FAQ says there is no public API against its own docs. Our Sprout Social vs Sprinklr comparison covers the same contradiction for social listening buyers. Amplitude's pricing page sells Heatmaps as a Plus feature against its own Session Replay documentation. Our Hotjar vs Amplitude comparison covers the same gap for buyers evaluating behavioral analytics tools.

The Cognism and ZoomInfo comparison walks the current naming. It matters because a stale competitor page is the source an AI engine reaches for when the vendor's own page is thin.

Security and compliance risks of running unsupported software

The number every EOL article quotes is $4.44 million. IBM replaced it on 29 July 2026: the global average cost of a data breach is now $4.99 million, a 12% rise and a record, drawn from 602 organisations breached between March 2025 and February 2026 across 16 countries and 17 industries. IBM prices a security skills shortage at $179,635 above that average.

$4.99M
The figure most EOL pages still get wrong

$4.44 million was IBM's 2025 number. IBM replaced it 29 July 2026 with $4.99 million, a 12% record high across 602 breached organisations. Pages still quoting $4.44 million are citing a figure IBM itself retired.

Unpatched vulnerabilities are the mechanism. Once security patches stop, every disclosed flaw in that supported version stays open permanently, leaving systems exposed to cyber threats that a patched neighbour shrugs off. Outdated systems accumulate security vulnerabilities; EOL systems never shed them, and each one is a significant risk that compounds with the next.

Compliance issues arrive on a separate clock. PCI-DSS treats unsupported software as a control failure with or without an incident, so compliance status can fail an audit on a product that has caused zero security breaches. Non compliance carries legal penalties that land long before the cybersecurity risks convert into data breaches.

How to check the lifecycle status of software you already run

Five checks, each under a minute, ordered by how often they settle it:

  1. Request the pricing page and read the HTTP status code. A 301 to another domain is an acquisition that has finished.
  2. Compare plan names on the pricing page against the help centre. Two vocabularies means one of them stopped being maintained.
  3. Read the API reference against the marketing FAQ. Docs are updated by the team that ships; FAQs are not.
  4. Check the changelog date. A product with no release note in eighteen months is nearing EOS whatever the sales team says.
  5. Check ownership. Acquisition announcements name the acquirer; the product page rarely does.

Run these as part of scheduled risk assessments across the estate. Renewal week is too late. Support tickets are the worst signal available, because specialized support queues stay staffed long after development stops.

Managing EOL and building a phased migration plan

Ignoring EOL costs more than the migration does. Legacy systems consume engineering time on compatibility issues that a supported product would have absorbed, and the operational inefficiencies compound: unexpected downtime, increased downtime during recovery, reduced productivity while people work around bugs nobody will fix. Increased costs show up as headcount, never as a line item.

A phased migration plan starts by mapping which business processes touch obsolete products, then sequences the swaps by blast radius. Plan ahead against the product's lifecycle over the renewal date. Alternative solutions get evaluated against future needs, and new solutions have to survive a five-year horizon, because the replacement has to be a long term solution and not a second migration in three years.

Isolate before you migrate

Risk mitigation during the overlap is unglamorous: isolate the unsupported software behind a firewall, freeze its integrations, and monitor it as hostile. That buys a smooth transition and helps minimize disruption to the teams still on it, containing the compatibility problems to one system instead of the estate.

Strategic planning here means one thing in practice: knowing which EOS dates land in the next eighteen months before finance sees them. A strategic approach to managing EOL software beats an emergency one by the cost of the emergency.

The business impact of getting this wrong is measured in significant challenges no one budgeted for. New software has migration costs you can forecast. Modern tools have training costs you can forecast. Running EOL software has a $4.99 million tail you cannot.

Stay informed by subscribing to vendor announcements where they exist, and by scripting the status-code check where they do not.

Frequently asked questions

What is the difference between EOL and deprecation?

Deprecation is a warning; EOL is the end. A deprecated feature still works and still receives bug fixes, and the vendor has published a replacement. EOL means development has stopped and no new features, security updates or support services are coming.

Does deprecated mean no longer supported?

No. Deprecated software is still supported and still gets fixes. It is marked for removal at a future date, which is the point of the label.

What does sunset mean for software?

Sunset is a vendor's word for the same event as EOL, chosen because it sounds gentler. Sunsetting a product means the vendor has set a date after which it stops selling, supporting and running it.

What is meant by legacy software?

Legacy software is software still in production that the organisation has decided not to develop further. It is a status the buyer assigns; EOL is a status the vendor assigns. Legacy systems are frequently still under official support.

What is EOL vs EOS?

EOS is the end of technical support with the software still running. EOL is the end of the product. On Microsoft's Fixed Policy products EOS is the published gate and paid extended support is the only route past it.

Can I still use Windows 10 after the end of life date?

Yes, and Microsoft says so directly: the computer "will still function." It receives no security updates, no feature updates and no technical support unless enrolled in Extended Security Updates, which run through 12 October 2027.

Bottom line

The EOL vocabulary was built for software you install, where the vendor owns a lifecycle table and publishes EOS dates against it. It does not transfer to SaaS, where a product ends in a redirect and the vendor's own help centre keeps answering questions about it for years. Two AI engines asked directly if Hotjar still exists both said yes, and both missed the 301 that is the whole answer. Check the status code yourself.

Sources, and what no vendor named here publishes

Windows 10 lifecycle dates, the Extended Security Updates prices and the end-of-support definitions are Microsoft's own, read off learn.microsoft.com, support.microsoft.com and microsoft.com. The breach cost is IBM's Cost of a Data Breach Report 2026, published 29 July 2026. The Hotjar redirect was checked by requesting hotjar.com/pricing and reading the response code; the plan names come from hotjar.com and help.hotjar.com. Sprout Social's API documentation is at api.sproutsocial.com. The complaint counts and quotes are from Hacker News (news.ycombinator.com/item?id=38749250). AI engine responses were collected on 9 August 2026 through the DataForSEO AI Optimization API with web search enabled, and both transcripts are dated because engine behaviour on these questions has changed inside a week before. All URLs accessed 9 August 2026. Hotjar publishes no end of life date, no end of support date and no support window for the product; Sprout Social publishes no deprecation policy; Amplitude publishes no plan-gate changelog; and neither Cognism nor 6sense dates its competitor pages.