Legacy React versions secure for as long as you need.

Supported Versions: 16, 17

NES for React is HeroDevs' commercially supported, drop-in replacement for legacy React 16 and 17, delivering ongoing CVE fixes and compliance coverage. It buys your team the time to migrate on your schedule.

TRUSTED BY ENTERPRISE

Google logoMicrosoft logoFinra logoBank Santander Logo
Hitachi LogoWorkday logoDropbox logo

Legacy React 16 and 17 are a  Compliance Risk

React does not have an official Long-Term Support and End-of-Life policy, community commitment to apply only critical security fixes to earlier versions is a security and compliance risk for your organization.

Your React-based apps exposed

AI is discovering more software vulnerabilities than ever before. At any time you can be exposed across your entire frontend estate,

An open audit finding with no remediation path

PCI DSS, HIPAA, SOC 2, FedRAMP, DORA, NIS2, among others expect software to be actively maintained. Legacy versions turn audits into a finding leaders can't explain to auditors.

A major-version upgrade is a project, not a patch

Moving React 16 and 17 to  version 18 and then 19 means rewrites and weeks of regression QA — $50K–$250K per codebase, across dozens of apps.

Security, compliance, and continuity, solved together in one simple drop-in replacement.

NES for React picks up exactly where the open source project leaves off, with SLA-backed fixes and a documented patch history you can hand to an auditor.

Security

NES provides HeroDevs commitment  to deliver CVE fixes on legacy versions, closing the window attackers depend on to exploit.

CVE fixes across all severity levels

Covers react & react-dom on legacy versions 16 and 17

Vulnerability discovery on legacy versions

Compliance

Actively patched and commercially supported under SLA response time delivering CVE fixes — turning auditor's questions to formal commercial coverage.

Coverage for SOC 2, PCI DSS, HIPAA, FedRAMP, DORA, NIS2, among other standards, frameworks, and regulations

Documented patch history for auditors

Meet internal policies and customer compliance requirements

Business Continuity Risk

A true drop-in replacement that installs in seconds, so you migrate to the latest React version on your own schedule. Do not slow down your operation with failed audits, migrations, or potential vulnerability exploits.

Months or years of runway to migrate right

No app rewrites, no broken components

A fraction of migration cost

We had three options: 1) migrate to a new framework (expensive, time consuming and disruptive to planned roadmap), 2) maintain the framework ourselves (diversion of development resources), 3) engage with HeroDevs for never ending support as a subscription (budget able annual expense, no impact to dev plan). Implementation was super simple. With the implementation of the HeroDevs libraries, 100% of the known vulnerabilities in the AngularJS framework were remediated yielding a clean scan via Burp Suite for our monthly POA&M.

— ViTel Net
Enterprise healthcare IT

By leveraging HeroDevs' extended support, we were able to mitigate security risks, continue safe operation of the legacy application, and gain valuable time to plan a more sustainable long-term migration strategy, all without compromising on client experience or regulatory requirements.

— Financial services
Sanlam Private Wealth

We were caught in the classic technology dilemma: spend valuable engineering time updating a legacy system we were already planning to replace, or accept increasing security risk. Neither option aligned with our business objectives. [With NES] we maintained our security posture without compromising our strategic roadmap, all while achieving substantial cost savings.

Statista
Markus Wolf

Imagine telling your customers you can't deliver any of the features they've been asking for because you need to spend the next year rewriting code that already works. That's not a conversation any CTO wants to have. The impact [of NES] goes beyond just keeping our lights on. We've been able to invest in a completely new component library, improve user experiences, and deliver features that directly contribute to new customer acquisition. That wouldn't have been possible if we'd been stuck in migration mode.

— Keelvar
Valentina Roques

What changes the day you install NES.

Before — the pain

Apps stuck on legacy React 16 & 17

Security scanners flag vulnerabilities, there are no guaranteed upstream patches for legacy versions and when a new  CVE is disclosed, the window between disclosure and exploit is wide open across every React-based app.

After — with HeroDevs

Patched in place

NES drop-in replacement via npm with no app  code changes required. SLA-backed CVE fixes resume on react and react-dom for versions 16 and 17 — security scanners go quiet and the exposure closes.

Before — the pain

An open finding with no answer

Internal audit, SOC 2, and other standards and regulations including customer security questionnaires required all software components to be supported and patched against known vulnerabilities.

After — with HeroDevs

Meeting compliance

NES provides the  CVE patching auditors require, satisfying the obligation that software be actively maintained under a commercial support contract, with committed SLA for security fixes as evidence.

Before — the pain

The migration cost and rushed execution

The total cost of ownership of a migration is always higher than initial plans driven by overtime, testing and the risk of production outages.

After — with HeroDevs

Migrate on your terms, not the clock

Teams get the breathing room to plan a proper React 18 or 19 migration while the library stays secure and compliant. A NES for React subscription cost a fraction of an emergency migration. The risk of CVE exploitation and business disruption is significantly reduced.

Contractual remediation — not volunteer goodwill.

NES is differentiated on the depth of community support for legacy React versions is goodwill with no committed response time, and modern auditors reject it. NES delivers CVE fixes for React 16 and 17 against contractual SLAs mapped to severity and exploit risk and quality of CVE discovery and React-specific expertise. HeroDevs partners with and funds the open source ecosystem directly.

HeroDevs monitors, validates, and ships SLA-backed fixes for React 16 and 17 — closing the widening gap between AI-accelerated discovery and patches on legacy versions.

10.0

CVSS · Critical

React is a security-relevant dependency

In 2025, CVE-2025-55182 ("React2Shell") — a critical remote-code-execution flaw in React 19 Server Components — scored a maximum CVSS 10.0. It doesn't affect 16 or 17, but it proves React itself is squarely in scope for attackers and auditors. With more AI-discovered vulnerabilities organizations are at an increased risk on legacy versions dependent on the volunteer goodwill to patch.

Why teams choose NES.

NES is differentiated on the depth and quality of CVE discovery and React-specific expertise. HeroDevs partners with and funds the open source ecosystem directly.

Others
Dedicated EOL React support
Automated process that only lists packages
CVE fixes by severity
CVE Numbering Authority (CNA)
Patch-delivery SLA
Drop-in npm replacement
Public CVE transparency
No commitment
No vulnerability discovery, not a CNA
With exceptions
Varies
Lists of all CVEs
HeroDevs logo
Purpose-built for React
All severity levels
Discovery and publication of CVEs
Committed
Same-name package, no code changes
Directory of patched CVEs

.Comparison based on publicly available vendor information and HeroDevs analysis, June 2026.

Switching to NES takes minutes.

package.json & .npmrc
# package.json
 "dependencies": {
    "react": "npm:@neverendingsupport/react@17.0.2-react-17.0.3",
    "react-dom": "npm:@neverendingsupport/react-dom@17.0.2-react-dom-17.0.3"
  }
}

# .npmrc
@neverendingsupport:registry=https://registry.nes.herodevs.com/npm/pkg/
//registry.nes.herodevs.com/npm/pkg/:_authToken=<nes-access-token>

npm install react react-dom
1

Select your version

Available in HeroDevs NES registry. NES for React versions 16 and 17.

2

Set up your token

Add your HeroDevs auth token so your environment can pull the patched packages securely.

3

Drop it in

Install the NES version. No application code changes required.

4

Security and meet compliance

Actively patched and commercially supported to secure your apps and meet compliance.

A defensible answer for every standard, framework, or regulation.

Legacy software  and unofficial community support undermines patch-management expectations across regulations worldwide. NES gives you a maintained, vendor-backed library with committed SLAs and a documented patch history to show auditors and regulators.

PCI DSS

US

Req. 6.3.3 requires known vulnerabilities to be patched, including a 30-day SLA for critical issues. Legacy React with no patch means immediate non-compliance — NES restores the patch path.

HIPAA

US

Unsupported components make it hard to show reasonable safeguards for systems handling ePHI. NES provides active maintenance and documented risk reduction.

SOC 2

Global

Trust Services Criteria expect timely vulnerability remediation and patch management. Legacy components with no security patches translate to failing certification.

FedRAMP

US

Baselines build on NIST SI-2, requiring flaws to be corrected and security updates installed within defined timeframes. Unpatched legacy software in government cloud does not meet compliance.

DORA

EU

Treats legacy software as a resilience flaw for financial ICT assets. NES sustains a documented patch-management program for critical systems.

NIS2 Directive

EU

Article 21 covers patching, vulnerability and supply-chain management. Legacy unpatched software is effectively non-compliant where it creates risk.

GDPR

EU

Article 32 expects "state of the art" technical measures. Running unsupported legacy software is difficult to defend after a breach — NES keeps the dependency maintained.

NIST CSF 2.0

US

Control PR.PS-02 requires organizations to actively maintain or remove vulnerable software based on risk. NES enables compliance without forced upgrade or removal

Cyber Resilience Act

US

Requires vulnerabilities in products and their components to be handled effectively during the support period. NES keeps front-end components covered.

ISO/IEC 27001:2022

Global

Vulnerability Management and Configuration Management controls require identifying technical vulnerabilities and keeping software within secure standards. NES restores control posture with patch availability for EOL software.

CIS Controls AU

control 7 (Continuous Vulnerability Management) and Control 2 (Software Asset Inventory) treat software that no longer receives security updates as inherently vulnerable. NES keep software patched and auditable.

Commercial Contracts UK

Many organizations are contractually prohibited from shipping unsupported software. NES provides the vendor-backed answer your own polices require.

React-specific expertise — and your whole front end under one contract.

Patches are developed by HeroDevs engineers with deep React and JavaScript-ecosystem experience, who proactively discover and remediate vulnerabilities on end-of-life open source. Consolidate NES for React alongside NES for Next.js, Node.js, and Express NES under a single vendor agreement.  HeroDevs gives back through a $20M open source sustainability fund, supporting open source projects with grants from $2,500 to $250,000.

React 16 & 17

react + react-dom coverage

NES for Next.js

Support for end-of-life Next.js versions

NES for Node.js & Express

Full-stack frontend & backend continuity

Frequently Asked Questions

What is Never-Ending Support (NES) for React?
Which React versions does NES support?
Is NES for React a drop-in replacement?
Does NES cover react-dom?
Does NES for React help with compliance?

Contact Us

Got questions about Never-Ending Support for your open-source library? We're here to help!

Discover how HeroDevs NES Products can keep your systems secure and compliant.

Learn how our solutions can deliver value to your organization.

Get detailed pricing information tailored to your needs.

Google logoLilly logoAbbott logoBox logoEG logoHitachi logoDropbox logoNHS logoWorkday logoFinra logoMicrosoft logoSantander logo
Talk to an Expert

By submitting the form I acknowledge receipt of our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.