According to a recent LinkedIn post from HeroDevs, the company is drawing attention to continued heavy usage of older React 16 and 17 versions, which it notes still see a combined 3.5 million to 3.6 million weekly downloads despite no longer receiving security patches from the React team. The post suggests that this creates ongoing exposure to unfixed CVEs across all severity levels for organizations that have not upgraded.
The company’s LinkedIn post highlights that HeroDevs is now offering its Never Ending Support (NES) service specifically for React 16.x and 17.x, positioning it as a way to provide ongoing CVE fixes under contractual SLAs. The post indicates that the solution is designed as a drop-in npm registry replacement requiring no code refactoring, and emphasizes the presence of a named vendor and documented patch history to support auditors and security reviews.
For investors, the post suggests HeroDevs is targeting a sizable installed base of legacy React applications with a compliance- and security-focused support product. If enterprises facing regulatory pressure adopt NES to mitigate end-of-life risk, this could contribute to recurring support revenue and strengthen HeroDevs’ positioning within the application security and open-source maintenance niche.
The emphasis on contractual SLAs, audit-ready documentation, and minimal integration friction may appeal to risk-averse enterprise customers, particularly those constrained from rapidly upgrading critical front-end stacks. This approach could differentiate HeroDevs from informal open-source maintenance options and, if scaled, could create a defensible niche around long-term commercial support for widely used but unsupported open-source components.

