firstly: Thanks for upgrading the version of PHP to one that is supported. There’s nothing more awkward than chairing a whole company risk and compliance meeting only to find that the software you use for managing Risk and Compliance is, itself, classified as a risk by the vulnerability scanning software.
On that subject the vulnerability scanner also detected Bootstrap 3.4.1, which was confirmed manually and according to google I can find is also EOL : End of Life Status Bootstrap 4 · Bootstrap v4.6
Are there plans to upgrade Bootstrap to a supported version??