Secure drop-in replacements for Lodash versions  3.x, 4.x

Lodash NES

Lodash Never-Ending Support (NES) keeps you compliant, secure, and audit-ready without an unplanned migration or risky patchwork.

Patch CVEs, Meet Internal SLAs, Pass Audits — in Minutes.

Talk to our Experts
Lodash.js logo

Solving Real Problems with NES

Lodash powers mission-critical apps across the web, yet the project is effectively unmaintained. Over 1.5 million weekly downloads still come from Lodash 3.x alone, and millions more use outdated patches of v4. But when CVEs appear, you’re on your own. There’s no roadmap, no maintainer response, and no clear future.
Lodash receives ~70 million downloads per week.
1.5M+ weekly downloads still come from v3.10.1 — a version over 10 years old.
No commits in over 3 months.
No Lodash v5.0. No roadmap.
The last security patch was released in 2021

HeroDevs NES keeps end-of-life versions of Lodash secure and compliant, remediating the concerns of:

Security-Conscious Teams
Get ahead of the CVE backlog without relying on an upstream that no longer patches your version.
Compliance-Driven Organizations
Stay aligned with PCI, HIPAA, and internal audit policies with documented patch support.
Resource-Strained Dev Teams
Keep building new features while we handle the hard parts of legacy maintenance.
Enterprises with Locked-In Infrastructure
When your infrastructure can't jump Lodash versions overnight, we make it safe to wait.

Lodash NES

is a secure drop-in replacement for

Lodash

and takes just a few minutes to set up.

Step 1
Update your package.json
Step 2
Set up token
Step 3
Install & Run!

What is Never-Ending Support?

Security icon
Security Fixes
A new version of Lodash NES will be released each time we find, validate, and fix a security issue.
Compatibility icon
Drop-In Compatibility
A direct replacement for your framework—no migrations, no rewrites, just ongoing support.
SLA Compliance icon
SLA Compliance
HeroDevs provides SLAs that ensure compliance by providing incident response and remediation in accordance with industry-standard regulations, including SOC 2, FedRAMP, PCI, and HIPAA.
Learn more.
Team of Experts icon
Team of Experts
Lodash NES is built by dedicated senior-level javascript and security engineers.
Easy to install icon
Easy to Install
Our simple drop-in replacement means all you have to do is change your package.json and rebuild your project. No code changes or find & replace required.
Shield icon
Intellectual Property Protection
Lodash NES is not only secure; HeroDevs also offers enterprise-level protection for all products.
Learn more.

Why HeroDevs?

Complete Security & Compliance graphic

No-Code Change Solution

Requires zero changes to application code, a truly drop-in replacement. HeroDevs essentially outsources the Lodash security upgrade to themselves, minimizing risk and effort for your team.
Complete Security & Compliance graphic

Professional, Ongoing Support vs. One-Time Fix

We provide a continuous support relationship, proactively handling issues as they arise, unlike a one-off patch.
Complete Security & Compliance graphic

Expertise and Focus

Our engineers specialize in maintaining legacy open source libraries from a security standpoint resulting in deep knowledge of Lodash for confident patching and testing.
Complete Security & Compliance graphic

Track Record in LTS

HeroDevs is known for supporting other EOL technologies like AngularJS and Vue 2, demonstrating our ability to keep critical open-source projects secure post-EOL.
SUPPORT

Frequently Asked Questions

Below are common questions our customers have. Of course, we’re happy to meet with you and answer these and other questions you might have.
How do I install Lodash NES?
Why do I need Lodash NES?
What Lodash versions does NES support?
Does HeroDevs have an SLA for Lodash NES?
How does licensing work?

Related Products

If you're leveraging this technology, chances are you're also using complementary systems that face similar end-of-life (EOL) challenges.

Explore our related NES products that offer proactive, comprehensive support for your entire tech stack to ensure continuity, security, and innovation across all your essential technologies.
Leaping over technology stacks in a single bound!

Defeat Your Technical Villains

Whether it's continuous support through our Never-Ending Support (NES) library or our unparalleled professional services to get you migrated and moving forward, HeroDevs is to the rescue!

Contact Us

Got questions about Never-Ending Support for your open-source library? We're here to help!

Discover how HeroDevs NES Products can keep your systems secure and compliant.

Learn how our solutions can deliver value to your organization.

Get detailed pricing information tailored to your needs.

Trusted by industry leaders such as
Microsoft LogoBank Santander Logo
SAP LogoFinra LogoCapital One LogoGeneral Electric LogoUnqork LogoGoogle LogoValid 8 logoQueenslandRail logoGSA logoDepartment of Health logo
Talk to an Expert

By clicking “submit” I acknowledge receipt of our Privacy Policy.

Thank you! Your submission has been received!
Please enter a company email.