# dayjs@1.11.13 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:27:04.000Z
- Files reviewed: 364
- Findings: 2 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/dayjs
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package dayjs@1.11.13 on Oct 4, 2026. An AI review of 364 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Prototype pollution / mutation

Finding ID: `NPS-091779B21B3C`

File: `plugin/badMutable.js:1`

The plugin intentionally mutates the prototype of the Day.js library (n.$g, n.set, n.startOf, n.add, n.locale, n.daysInMonth, n.isSame, n.isBefore, n.isAfter). While this is the stated purpose of a 'badMutable' plugin, monkey-patching core library methods can introduce unexpected behavior and potential security risks if these methods are used in security-sensitive contexts (e.g., date validation, token expiry checks).

### [medium] Top-level side effects

Finding ID: `NPS-635F912DCA02`

File: `plugin/badMutable.js:1`

The code executes immediately upon import and modifies global/prototype behavior of the Day.js library without explicit user opt-in beyond installing the plugin. This could affect other code relying on Day.js immutability.

### [low] Unsafe dynamic constructor invocation

Finding ID: `NPS-50DA6880678E`

File: `esm/plugin/arraySupport/index.js:22`

Uses Function.prototype.bind.apply(Date, [null].concat(date)) to construct a Date instance. While this pattern is often used to support a variable number of arguments to Date's constructor, it relies on dynamic function construction semantics that are occasionally seen in obfuscated or evasive code. In this context the target is Date (not eval/Function for arbitrary code), and the input is the plugin's own 'date' array, so it is not remote code execution, but it is an unnecessarily obscure and fragile construct that could mask malicious intent if altered.

### [low] dynamic code execution

Finding ID: `NPS-495CA1B032FE`

File: `plugin/arraySupport.js:1`

The code uses Function.prototype.bind.apply(Date, [null].concat(t)) as a way to dynamically construct Date objects. While this is not eval, it dynamically invokes the Date constructor with a variable number of arguments derived from user input. However, this is a known idiom for spreading arguments and not an injection vector by itself, as Date is a built-in. Still, it is a form of dynamic invocation that could be flagged in a strict security review.

### [low] monkey-patching

Finding ID: `NPS-9918DBF42852`

File: `plugin/arraySupport.js:1`

The plugin overrides the parse method of the Day.js prototype. This is a common plugin pattern but means any code using Day.js after this plugin loads will have its parsing behavior altered. This could be abused by a malicious plugin to intercept or modify date parsing globally, though no data exfiltration or other malicious behavior is present here.

## Files reviewed

- `esm/plugin/arraySupport/index.js` (medium): No exfiltration, credential harvesting, mining, backdoors, process spawning, or install-time execution was found; the only notable concern is a non-standard dynamic Date construction idiom that carries low risk.
- `plugin/arraySupport.js` (medium): The code is a legitimate Day.js plugin for array-based date parsing; it uses Function.prototype.bind.apply for argument spreading, which is not malicious, but the dynamic invocation and prototype patching warrant a low-severity warning.
- `plugin/badMutable.js` (medium): The plugin is not overtly malicious but mutates the Day.js prototype at import time, which could cause unintended side effects or weaken date-related security assumptions in consuming applications.
- `esm/constant.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/index.js` (safe): No malicious patterns detected
- `esm/locale/af.js` (safe): No malicious patterns detected
- `esm/locale/am.js` (safe): No malicious patterns detected
- `esm/locale/ar-dz.js` (safe): No malicious patterns detected
- `esm/locale/ar-iq.js` (safe): This is a standard Arabic (Iraq) locale configuration file for the dayjs library with no malicious patterns detected.
- `esm/locale/ar-kw.js` (safe): No malicious patterns detected
- `esm/locale/ar-ly.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition.
- `esm/locale/ar-ma.js` (safe): No malicious patterns detected; file is a standard dayjs locale definition with only static data and pure functions.
- `esm/locale/ar-sa.js` (safe): No malicious patterns detected; this is a legitimate dayjs locale definition for Arabic (Saudi Arabia) containing only static translation strings and simple formatting functions.
- `esm/locale/ar-tn.js` (safe): No malicious patterns detected; the file is a standard Day.js Arabic (Tunisia) locale definition with static translations and no network, filesystem, process, or dynamic execution behavior.
- `esm/locale/ar.js` (safe): No malicious patterns detected; the file is a standard dayjs Arabic locale definition with no network, filesystem, process, or dynamic code execution behavior.
- `esm/locale/az.js` (safe): No malicious patterns detected
- `esm/locale/be.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition file for Belarusian with only static locale data and a benign ordinal function.
- `esm/locale/bg.js` (safe): No malicious patterns detected; this is a standard dayjs Bulgarian locale file with no network, filesystem, process, or dynamic execution behavior.
- `esm/locale/bi.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition file for Bislama.
- `esm/locale/bm.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Bambara containing only static localization data and a locale registration call.
- `esm/locale/bn-bd.js` (safe): No malicious patterns detected; this is a standard dayjs locale file with only string replacement and locale configuration logic.
- `esm/locale/bn.js` (safe): No malicious patterns detected
- `esm/locale/bo.js` (safe): No malicious patterns detected; this is a legitimate Day.js Tibetan locale file with static translations and no dynamic behavior.
- `esm/locale/br.js` (safe): No malicious patterns detected
- `esm/locale/bs.js` (safe): No malicious patterns detected
- `esm/locale/ca.js` (safe): No malicious patterns detected
- `esm/locale/cs.js` (safe): No malicious patterns detected
- `esm/locale/cv.js` (safe): No malicious patterns detected
- `esm/locale/cy.js` (safe): No malicious patterns detected
- `esm/locale/da.js` (safe): This is a standard Day.js locale definition file for Danish with no malicious patterns, network calls, or dynamic code execution.
- `esm/locale/de-at.js` (safe): This is a standard Day.js locale definition file for German (Austria) with no malicious patterns, external calls, or dynamic code execution.
- `esm/locale/de-ch.js` (safe): No malicious patterns detected; this is a legitimate dayjs locale definition file with only static strings and a simple formatter.
- `esm/locale/de.js` (safe): This is a standard Day.js German locale file with no malicious patterns, network calls, process spawning, or obfuscated code.
- `esm/locale/dv.js` (safe): This is a standard dayjs locale definition file for Dhivehi with no malicious patterns, no external calls, and no dynamic code execution.
- `esm/locale/el.js` (safe): No malicious patterns detected
- `esm/locale/en-au.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition file for English (Australia) with no network, filesystem, process, or dynamic code execution behavior.
- `esm/locale/en-ca.js` (safe): No malicious patterns detected
- `esm/locale/en-gb.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition with no network, filesystem, process execution, or dynamic code evaluation.
- `esm/locale/en-ie.js` (safe): This is a standard dayjs locale definition file for English (Ireland) with no malicious patterns detected.
- `esm/locale/en-il.js` (safe): This is a standard Day.js locale definition file containing only static translation strings and formatting configuration with no malicious patterns.
- `esm/locale/en-in.js` (safe): No malicious patterns detected
- `esm/locale/en-nz.js` (safe): No malicious patterns detected
- `esm/locale/en-sg.js` (safe): No malicious patterns detected
- `esm/locale/en-tt.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition with no network, filesystem, process, or dynamic code execution behavior.
- `esm/locale/en.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/locale/eo.js` (safe): No malicious patterns detected; the file is a legitimate dayjs Esperanto locale definition with only static data and a simple ordinal function.
- `esm/locale/es-do.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Spanish (Dominican Republic).
- `esm/locale/es-mx.js` (safe): No malicious patterns detected
- `esm/locale/es-pr.js` (safe): No malicious patterns detected in the dayjs locale file
- `esm/locale/es-us.js` (safe): No malicious patterns detected
- `esm/locale/es.js` (safe): No malicious patterns detected; this is a standard dayjs Spanish locale definition file.
- `esm/locale/et.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition with no network, filesystem, process, or obfuscated code.
- `esm/locale/eu.js` (safe): No malicious patterns detected
- `esm/locale/fa.js` (safe): This is a standard dayjs locale definition file for Persian with no malicious patterns, network activity, dynamic code execution, or suspicious behavior.
- `esm/locale/fi.js` (safe): No malicious patterns detected; this is a standard dayjs locale file for Finnish.
- `esm/locale/fo.js` (safe): No malicious patterns detected; the file is a standard dayjs Faroese locale definition with no network, filesystem, process, or dynamic code execution behavior.
- `esm/locale/fr-ca.js` (safe): No malicious patterns detected; the file is a standard French (Canada) locale definition for dayjs.
- `esm/locale/fr-ch.js` (safe): No malicious patterns detected; the file is a standard Day.js locale definition containing only static translation data and a simple ordinal function.
- `esm/locale/fr.js` (safe): No malicious patterns detected
- `esm/locale/fy.js` (safe): No malicious patterns detected; this is a legitimate dayjs locale definition file for Frisian.
- `esm/locale/ga.js` (safe): No malicious patterns detected
- `esm/locale/gd.js` (safe): This is a standard dayjs locale definition file for Scottish Gaelic with no malicious patterns, network calls, file access, or dynamic code execution.
- `esm/locale/gl.js` (safe): This is a legitimate dayjs Galician locale file with only static translations, no network, filesystem, process, or dynamic code execution patterns.
- `esm/locale/gom-latn.js` (safe): No malicious patterns detected
- `esm/locale/gu.js` (safe): No malicious patterns detected
- `esm/locale/he.js` (safe): No malicious patterns detected
- `esm/locale/hi.js` (safe): No malicious patterns detected; this is a standard dayjs Hindi locale definition file.
- `esm/locale/hr.js` (safe): No malicious patterns detected
- `esm/locale/ht.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Haitian Creole.
- `esm/locale/hu.js` (safe): No malicious patterns detected
- `esm/locale/hy-am.js` (safe): No malicious patterns detected
- `esm/locale/id.js` (safe): The file is a standard Day.js Indonesian locale definition with no malicious patterns, network activity, dynamic code execution, or filesystem access.
- `esm/locale/is.js` (safe): No malicious patterns detected
- `esm/locale/it-ch.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition file with no network, filesystem, or dynamic execution activity.
- `esm/locale/it.js` (safe): No malicious patterns detected; the file is a standard dayjs Italian locale definition with only static data and a trivial ordinal formatter.
- `esm/locale/ja.js` (safe): No malicious patterns detected; the file is a standard dayjs Japanese locale definition with no network, filesystem, process, or dynamic code execution behavior.
- `esm/locale/jv.js` (safe): No malicious patterns detected
- `esm/locale/ka.js` (safe): This is a standard dayjs locale definition file for Georgian with no malicious patterns, network activity, or dynamic code execution.
- `esm/locale/kk.js` (safe): No malicious patterns detected; file is a standard dayjs Kazakh locale definition with only static data and a locale registration call.
- `esm/locale/km.js` (safe): This is a standard Day.js locale definition file for Cambodian (km) with no malicious patterns, network activity, or dynamic code execution.
- `esm/locale/kn.js` (safe): No malicious patterns detected in this localization file for the dayjs library.
- `esm/locale/ko.js` (safe): No malicious patterns detected
- `esm/locale/ku.js` (safe): No malicious patterns detected; this is a standard dayjs Kurdish locale file with only string localization and number formatting logic.
- `esm/locale/ky.js` (safe): No malicious patterns detected
- `esm/locale/lb.js` (safe): No malicious patterns detected
- `esm/locale/lo.js` (safe): No malicious patterns detected; the file is a standard dayjs Lao locale definition with only static locale data and a locale registration call.
- `esm/locale/lt.js` (safe): No malicious patterns detected
- `esm/locale/lv.js` (safe): No malicious patterns detected
- `esm/locale/me.js` (safe): No malicious patterns detected
- `esm/locale/mi.js` (safe): No malicious patterns detected; this is a standard Day.js Maori locale definition file with static data and no network, filesystem, or code execution behavior.
- `esm/locale/mk.js` (safe): This is a standard dayjs locale definition file for Macedonian with no malicious patterns, network calls, or dynamic code execution.
- `esm/locale/ml.js` (safe): No malicious patterns detected
- `esm/locale/mn.js` (safe): No malicious patterns detected
- `esm/locale/mr.js` (safe): No malicious patterns detected
- `esm/locale/ms-my.js` (safe): No malicious patterns detected
- `esm/locale/ms.js` (safe): No malicious patterns detected; this is a standard Day.js Malay locale definition file with no network, file system, process, or dynamic code execution activity.
- `esm/locale/mt.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition file with no network, filesystem, or dynamic execution activity.
- `esm/locale/my.js` (safe): No malicious patterns detected
- `esm/locale/nb.js` (safe): No malicious patterns detected
- `esm/locale/ne.js` (safe): No malicious patterns detected
- `esm/locale/nl-be.js` (safe): This is a standard Day.js locale definition file for Dutch (Belgium) containing only static translation strings and formatting rules with no malicious patterns.
- `esm/locale/nl.js` (safe): No malicious patterns detected in this standard dayjs Dutch locale file
- `esm/locale/nn.js` (safe): No malicious patterns detected
- `esm/locale/oc-lnc.js` (safe): No malicious patterns detected
- `esm/locale/pa-in.js` (safe): No malicious patterns detected
- `esm/locale/pl.js` (safe): No malicious patterns detected
- `esm/locale/pt-br.js` (safe): This is a standard locale file for the dayjs library containing only Portuguese (Brazil) translations and no malicious patterns.
- `esm/locale/pt.js` (safe): No malicious patterns detected
- `esm/locale/rn.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition file with no data exfiltration, dynamic code execution, or suspicious behavior.
- `esm/locale/ro.js` (safe): No malicious patterns detected; the file is a standard dayjs Romanian locale definition with only static data and locale registration.
- `esm/locale/ru.js` (safe): No malicious patterns detected in the Russian locale file for dayjs; it contains only locale-specific date formatting data and functions.
- `esm/locale/rw.js` (safe): No malicious patterns detected
- `esm/locale/sd.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Sindhi with no network, file system, process, or dynamic execution activity.
- `esm/locale/se.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Northern Sami with only static data and locale registration.
- `esm/locale/si.js` (safe): No malicious patterns detected; the file is a standard Day.js Sinhalese locale definition with no network, filesystem, credential, or dynamic execution activity.
- `esm/locale/sk.js` (safe): The file is a standard dayjs Slovak locale definition with no malicious patterns, network calls, credential access, dynamic code execution, or install-time hooks.
- `esm/locale/sl.js` (safe): No malicious patterns detected
- `esm/locale/sq.js` (safe): No malicious patterns detected
- `esm/locale/sr-cyrl.js` (safe): No malicious patterns detected
- `esm/locale/sr.js` (safe): No malicious patterns detected; the file is a standard Day.js Serbian locale definition with no network, filesystem, process, or dynamic code execution activity.
- `esm/locale/ss.js` (safe): No malicious patterns detected
- `esm/locale/sv-fi.js` (safe): No malicious patterns detected
- `esm/locale/sv.js` (safe): This is a standard dayjs Swedish locale file with no suspicious behavior; it only defines locale data and registers it via dayjs.locale().
- `esm/locale/sw.js` (safe): No malicious patterns detected
- `esm/locale/ta.js` (safe): No malicious patterns detected
- `esm/locale/te.js` (safe): No malicious patterns detected
- `esm/locale/tet.js` (safe): No malicious patterns detected
- `esm/locale/tg.js` (safe): No malicious patterns detected
- `esm/locale/th.js` (safe): No malicious patterns detected; this is a standard dayjs Thai locale definition file with only static data and a locale registration call.
- `esm/locale/tk.js` (safe): No malicious patterns detected
- `esm/locale/tl-ph.js` (safe): No malicious patterns detected
- `esm/locale/tlh.js` (safe): No malicious patterns detected
- `esm/locale/tr.js` (safe): No malicious patterns detected; the file is a standard dayjs Turkish locale definition with no network, filesystem, process, or dynamic code execution behavior.
- `esm/locale/tzl.js` (safe): No malicious patterns detected
- `esm/locale/tzm-latn.js` (safe): This is a standard dayjs locale definition file containing only static translation strings and configuration; no malicious patterns detected.
- `esm/locale/tzm.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition with static data and no dangerous operations.
- `esm/locale/ug-cn.js` (safe): No malicious patterns detected
- `esm/locale/uk.js` (safe): No malicious patterns detected
- `esm/locale/ur.js` (safe): No malicious patterns detected
- `esm/locale/uz-latn.js` (safe): No malicious patterns detected
- `esm/locale/uz.js` (safe): No malicious patterns detected
- `esm/locale/vi.js` (safe): No malicious patterns detected; this is a standard dayjs Vietnamese locale file containing only static translations and configuration.
- `esm/locale/x-pseudo.js` (safe): This is a standard dayjs locale definition file with static string data, no malicious patterns, network calls, dynamic execution, or filesystem access detected.
- `esm/locale/yo.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Yoruba.
- `esm/locale/zh-cn.js` (safe): No malicious patterns detected
- `esm/locale/zh-hk.js` (safe): No malicious patterns detected; this is a standard dayjs locale definition for Chinese (Hong Kong) with only static string data and locale callbacks.
- `esm/locale/zh-tw.js` (safe): No malicious patterns detected
- `esm/locale/zh.js` (safe): No malicious patterns detected; this is a standard Day.js Chinese locale definition file with no network, file system, process, or obfuscated code.
- `esm/plugin/advancedFormat/index.js` (safe): No malicious patterns detected; the code only extends date formatting with replacement tokens and performs no network, file, process, or credential operations.
- `esm/plugin/badMutable/index.js` (safe): No malicious patterns detected; the code only patches dayjs prototype methods for mutable behavior, with no network, filesystem, process, or dynamic code execution activity.
- `esm/plugin/bigIntSupport/index.js` (safe): No malicious patterns detected; the code is a legitimate dayjs plugin that adds BigInt date support with no exfiltration, obfuscation, or system access.
- `esm/plugin/buddhistEra/index.js` (safe): No malicious patterns detected; the code is a benign dayjs plugin for Buddhist Era calendar formatting, with no network, filesystem, process, or dynamic execution activity.
- `esm/plugin/calendar/index.js` (safe): The code is a standard Day.js calendar plugin implementation with no malicious patterns such as data exfiltration, obfuscation, or dynamic execution.
- `esm/plugin/customParseFormat/index.js` (safe): No malicious patterns detected
- `esm/plugin/dayOfYear/index.js` (safe): This is a clean day-of-year plugin for Day.js with no malicious patterns, external calls, or dangerous operations.
- `esm/plugin/devHelper/index.js` (safe): No malicious patterns detected; the code only adds development-time console warnings for date parsing and locale usage.
- `esm/plugin/duration/index.js` (safe): No malicious patterns detected
- `esm/plugin/isBetween/index.js` (safe): No malicious patterns detected
- `esm/plugin/isLeapYear/index.js` (safe): The code is a simple, non-malicious addition of an isLeapYear method to a prototype, with no suspicious patterns or security concerns.
- `esm/plugin/isMoment/index.js` (safe): No malicious patterns detected
- `esm/plugin/isSameOrAfter/index.js` (safe): No malicious patterns detected; the file defines a simple date-comparison plugin method with no network, filesystem, process, or dynamic execution activity.
- `esm/plugin/isSameOrBefore/index.js` (safe): No malicious patterns detected
- `esm/plugin/isToday/index.js` (safe): No malicious patterns detected
- `esm/plugin/isTomorrow/index.js` (safe): No malicious patterns detected
- `esm/plugin/isYesterday/index.js` (safe): No malicious patterns detected
- `esm/plugin/isoWeek/index.js` (safe): No malicious patterns detected; the code implements ISO week date calculations as a standard date library plugin.
- `esm/plugin/isoWeeksInYear/index.js` (safe): No malicious patterns detected
- `esm/plugin/localeData/index.js` (safe): The code is a standard locale data plugin for Day.js and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution.
- `esm/plugin/localizedFormat/index.js` (safe): No malicious patterns detected
- `esm/plugin/localizedFormat/utils.js` (safe): No malicious patterns detected; the code only performs string formatting and regex replacement for date/time localization.
- `esm/plugin/minMax/index.js` (safe): No malicious patterns detected; the code is a legitimate dayjs plugin for computing min/max dates.
- `esm/plugin/negativeYear/index.js` (safe): No malicious patterns detected; the code is a legitimate Day.js plugin for parsing negative year dates.
- `esm/plugin/objectSupport/index.js` (safe): No malicious patterns detected; the code is a legitimate dayjs plugin for object-based date manipulation.
- `esm/plugin/pluralGetSet/index.js` (safe): No malicious patterns detected; the code simply adds plural aliases to prototype methods for a date library plugin.
- `esm/plugin/preParsePostFormat/index.js` (safe): No malicious patterns detected; the code is a legitimate day.js plugin that safely overrides parse and format methods to apply locale-specific preprocessing and postformatting.
- `esm/plugin/quarterOfYear/index.js` (safe): No malicious patterns detected
- `esm/plugin/relativeTime/index.js` (safe): No malicious patterns detected; this is a legitimate relative time plugin for the Day.js library.
- `esm/plugin/timezone/index.js` (safe): This is a legitimate Day.js timezone plugin implementation that uses standard Intl.DateTimeFormat APIs with no malicious patterns detected.
- `esm/plugin/toArray/index.js` (safe): No malicious patterns detected; the code only adds a toArray method to a prototype.
- `esm/plugin/toObject/index.js` (safe): The code is a simple plugin that adds a toObject method to a prototype, returning date components, with no malicious patterns detected.
- `esm/plugin/updateLocale/index.js` (safe): No malicious patterns detected
- `esm/plugin/utc/index.js` (safe): The code is a legitimate Day.js UTC plugin that performs date/time calculations and formatting, with no malicious patterns or security concerns.
- `esm/plugin/weekOfYear/index.js` (safe): This Day.js plugin implements week-of-year calculation logic using inherited library methods, with no network, filesystem, process, or dynamic code execution patterns.
- `esm/plugin/weekYear/index.js` (safe): No malicious patterns detected
- `esm/plugin/weekday/index.js` (safe): No malicious patterns detected; the code is a benign dayjs plugin that adds a weekday method to the library's prototype.
- `esm/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `locale/af.js` (safe): No malicious patterns detected
- `locale/am.js` (safe): No malicious patterns detected; the file is a standard Day.js Amharic locale definition with no network, filesystem, or execution risks.
- `locale/ar-dz.js` (safe): No malicious patterns detected; this is a standard Day.js locale definition for Arabic (Algeria) with only static locale data and a UMD wrapper.
- `locale/ar-iq.js` (safe): No malicious patterns detected
- `locale/ar-kw.js` (safe): This is a standard Day.js Arabic (Kuwait) locale file containing only translation strings and date formatting logic, with no malicious patterns detected.
- `locale/ar-ly.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Arabic (Libya).
- `locale/ar-ma.js` (safe): No malicious patterns detected; this is a standard Day.js Arabic (Morocco) locale file containing only static localization data and a UMD wrapper.
- `locale/ar-sa.js` (safe): No malicious patterns detected; the file is a standard Day.js Arabic (Saudi Arabia) locale definition with no suspicious network, filesystem, process, or obfuscated code.
- `locale/ar-tn.js` (safe): No malicious patterns detected
- `locale/ar.js` (safe): No malicious patterns detected
- `locale/az.js` (safe): No malicious patterns detected
- `locale/be.js` (safe): No malicious patterns detected; the file is a standard dayjs locale definition for Belarusian.
- `locale/bg.js` (safe): No malicious patterns detected
- `locale/bi.js` (safe): No malicious patterns detected; the file is a standard Day.js locale definition for the Bislama language.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
