The current version used for php-date-formatter is vulnerable to Prototype Pollution: https://intel.aikido.dev/cve/AIKIDO-2025-10081 Fix: bump https://github.com/kartik-v/php-date-formatter/releases/tag/v1.3.7