Togoder security

npm package security report

@tanstack/query-core npm package: is it safe?

No malicious code found.

No issues Version 5.104.1 Files reviewed 119 Size 933.1 KB Scanned

Summary

Togoder Security scanned the npm package @tanstack/query-core@5.104.1 on Oct 6, 2026. An AI review of 119 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Dynamic code execution

NPS-9B474C47B287

This is a wrapper for the platform's setTimeout/setInterval APIs. No eval, Function constructors, or other dynamic execution is present.

build/modern/timeoutManager.cjs

Files reviewed

FileVerdictWhat the reviewer saw
build/legacy/classPrivateFieldSet2-CukOTU3U.js safe This file contains only standard JavaScript private class field helper functions generated by the Oxc runtime, with no network, filesystem, process, credential, or dynamic execution behavior.
build/legacy/classPrivateFieldSet2-CvCEk6bM.cjs safe No malicious patterns detected; the file contains standard OXC runtime helper functions for private class field handling with no network, filesystem, process, or obfuscated code.
build/legacy/classPrivateMethodInitSpec-CgB-WYk3.js safe This is a standard JavaScript class private method initialization helper with no malicious patterns detected.
build/legacy/classPrivateMethodInitSpec-Nr6mgZRs.cjs safe No malicious patterns detected
build/legacy/environmentManager.cjs safe No malicious patterns detected; the code only implements a simple, documented environment detection toggle for TanStack Query.
build/legacy/environmentManager.js safe No malicious patterns detected
build/legacy/focusManager.cjs safe No malicious patterns detected; the code is a legitimate TanStack Query FocusManager implementation with only standard browser event handling.
build/legacy/focusManager.js safe No malicious patterns detected; the code is a legitimate focus manager from TanStack Query with only browser visibility event listeners and no network, filesystem, or process operations.
build/legacy/hydration.cjs safe No malicious patterns detected; the code is standard TanStack Query hydration/dehydration logic with no exfiltration, credential access, obfuscation, or process spawning.
build/legacy/hydration.js safe No malicious patterns detected
build/legacy/index.cjs safe No malicious patterns detected; this is a standard barrel index file re-exporting TanStack Query modules.
build/legacy/index.js safe No malicious patterns detected; the file is a clean re-export barrel for TanStack Query's legacy build.
build/legacy/infiniteQueryBehavior.cjs safe No malicious patterns detected
build/legacy/infiniteQueryBehavior.js safe No malicious patterns detected
build/legacy/infiniteQueryObserver.cjs safe No malicious patterns detected; the code is a standard TanStack Query InfiniteQueryObserver implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/legacy/infiniteQueryObserver.js safe This is a legitimate TanStack Query InfiniteQueryObserver implementation with no malicious patterns, network calls, file system access, or dynamic code execution.
build/legacy/mutation.cjs safe No malicious patterns detected; the code is a standard TanStack Query Mutation class implementation with no exfiltration, obfuscation, or process execution.
build/legacy/mutation.js safe This is a legitimate TanStack Query Mutation implementation with no malicious patterns detected
build/legacy/mutationCache.cjs safe No malicious patterns detected; the code implements a standard mutation cache for TanStack Query with no network, filesystem, process, or dynamic-eval activity.
build/legacy/mutationCache.js safe No malicious patterns detected
build/legacy/mutationObserver.cjs safe No malicious patterns detected; this is a standard TanStack Query MutationObserver module with no exfiltration, obfuscation, or process execution code.
build/legacy/mutationObserver.js safe This is a legitimate TanStack Query MutationObserver implementation with no malicious patterns detected.
build/legacy/notifyManager.cjs safe This file implements a legitimate notify/batching manager for TanStack Query with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
build/legacy/notifyManager.js safe Cleared by Jev triage; no further analysis needed
build/legacy/onlineManager.cjs safe No malicious patterns detected; the file is a standard TanStack Query online manager utility with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
Show 94 more files
FileVerdictWhat the reviewer saw
build/legacy/onlineManager.js safe No malicious patterns detected; the file is a standard TanStack Query online state manager using browser online/offline events.
build/legacy/queriesObserver.cjs safe This is a legitimate TanStack Query QueriesObserver implementation with no malicious patterns, network calls, dynamic code execution, or credential access.
build/legacy/queriesObserver.js safe No malicious patterns detected; the file is a legitimate build artifact of TanStack Query's QueriesObserver with no exfiltration, obfuscation, dynamic execution, or suspicious I/O.
build/legacy/query.cjs safe This is a legitimate TanStack Query library file containing only query state management logic with no malicious patterns.
build/legacy/query.js safe This is the standard TanStack Query core query implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution detected.
build/legacy/queryCache.cjs safe No malicious patterns detected; this is the legitimate TanStack Query QueryCache implementation with only local imports and standard cache management logic.
build/legacy/queryCache.js safe This is a legitimate TanStack Query QueryCache implementation with no malicious patterns, network calls, credential harvesting, or dynamic code execution.
build/legacy/queryClient.cjs safe No malicious patterns detected
build/legacy/queryClient.js safe No malicious patterns detected; this is a legitimate TanStack Query QueryClient implementation with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
build/legacy/queryObserver.cjs safe No malicious patterns detected; this is a legitimate TanStack Query QueryObserver implementation with standard observability, timing, and query management logic.
build/legacy/queryObserver.js safe This is a legitimate build artifact of TanStack Query's QueryObserver class; no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution were detected.
build/legacy/removable.cjs safe No malicious patterns detected; the code is a standard garbage-collection timer utility for cache entries with no network, filesystem, process, or dynamic code execution activity.
build/legacy/removable.js safe No malicious patterns detected; the code is a straightforward garbage collection timer utility with standard imports and no network, filesystem, process, or dynamic execution activity.
build/legacy/retryer.cjs safe The code is a legitimate retry utility for TanStack Query with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
build/legacy/retryer.js safe No malicious patterns detected; the code implements a standard retry utility for async operations with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
build/legacy/streamedQuery.cjs safe No malicious patterns detected; the code is a legitimate TanStack Query utility for streaming async iterables with no network, filesystem, process, or dynamic code execution behavior.
build/legacy/streamedQuery.js safe No malicious patterns detected; the file implements a standard streamed query helper with no exfiltration, credential harvesting, code execution, or suspicious runtime behavior.
build/legacy/subscribable.cjs safe No malicious patterns detected; the file is a straightforward implementation of a subscribable base class from the TanStack Query library with no network, filesystem, process, or dynamic code execution behavior.
build/legacy/subscribable.js safe No malicious patterns detected
build/legacy/timeoutManager.cjs safe This is legitimate TanStack Query timeout management code with no malicious patterns detected.
build/legacy/timeoutManager.js safe No malicious patterns detected
build/legacy/types.cjs safe No malicious patterns detected
build/legacy/types.js safe No malicious patterns detected; the file only defines and exports three Symbol constants and contains a source map reference.
build/legacy/utils.cjs safe No malicious patterns detected
build/legacy/utils.js safe No malicious patterns detected
build/modern/environmentManager.cjs safe No malicious patterns detected; the code only implements a simple, documented environment detection toggle for TanStack Query.
build/modern/environmentManager.js safe No malicious patterns detected
build/modern/focusManager.cjs safe No malicious patterns detected; the code is a standard FocusManager utility for TanStack Query that manages browser focus/visibility state without any security concerns.
build/modern/focusManager.js safe Cleared by Jev triage; no further analysis needed
build/modern/hydration.cjs safe No malicious patterns detected; the file contains standard TanStack Query hydration/dehydration logic with no network, filesystem, process, or dynamic execution abuse.
build/modern/hydration.js safe No malicious patterns detected; the code implements standard TanStack Query hydration/dehydration logic for serializing and restoring query cache state without any exfiltration, credential harvesting, obfuscation, or process execution.
build/modern/index.cjs safe No malicious patterns detected; this is a standard barrel index file re-exporting TanStack Query modules.
build/modern/index.js safe No malicious patterns detected; the file is a clean re-export barrel for TanStack Query's legacy build.
build/modern/infiniteQueryBehavior.cjs safe No malicious patterns detected; the code is a legitimate TanStack Query infinite query behavior implementation with no network, filesystem, process, or dynamic execution concerns.
build/modern/infiniteQueryBehavior.js safe No malicious patterns detected; the code is a legitimate TanStack Query infinite query behavior implementation.
build/modern/infiniteQueryObserver.cjs safe No malicious patterns detected
build/modern/infiniteQueryObserver.js safe No malicious patterns detected; the file is a standard TanStack Query InfiniteQueryObserver implementation with no exfiltration, credential harvesting, dynamic code execution, or other red flags.
build/modern/mutation.cjs safe No malicious patterns detected; this is standard TanStack Query mutation lifecycle code with no network exfiltration, credential harvesting, obfuscation, or process spawning.
build/modern/mutation.js safe This is legitimate TanStack Query mutation logic with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
build/modern/mutationCache.cjs safe No malicious patterns detected; the code implements a standard MutationCache class for a query library with no network, filesystem, process, or dynamic execution behavior.
build/modern/mutationCache.js safe No malicious patterns detected; the file is a standard MutationCache implementation from TanStack Query with no network, filesystem, process, or dynamic code execution concerns.
build/modern/mutationObserver.cjs safe No malicious patterns detected
build/modern/mutationObserver.js safe No malicious patterns detected; the code is a standard TanStack Query MutationObserver implementation with no exfiltration, credential harvesting, obfuscation, or process execution.
build/modern/notifyManager.cjs safe This file implements a legitimate notify/batching manager for TanStack Query with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
build/modern/notifyManager.js safe Cleared by Jev triage; no further analysis needed
build/modern/onlineManager.cjs safe No malicious patterns detected; the file is a benign implementation of TanStack Query's OnlineManager that only registers online/offline event listeners on the window object.
build/modern/onlineManager.js safe Cleared by Jev triage; no further analysis needed
build/modern/queriesObserver.cjs safe No malicious patterns detected; this is a legitimate TanStack Query QueriesObserver module with standard require imports and no data exfiltration, credential harvesting, obfuscation, or process spawning.
build/modern/queriesObserver.js safe This is a legitimate QueriesObserver implementation from TanStack Query with no malicious patterns detected.
build/modern/query.cjs safe No malicious patterns detected; this is legitimate TanStack Query library code with no exfiltration, obfuscation, credential harvesting, or process execution.
build/modern/query.js safe This is a legitimate TanStack Query core module with no malicious patterns detected
build/modern/queryCache.cjs safe No malicious patterns detected
build/modern/queryCache.js safe This is the legitimate QueryCache source from TanStack Query with no malicious patterns, network exfiltration, credential access, dynamic code execution, or unsafe process/file operations.
build/modern/queryClient.cjs safe This is the standard TanStack QueryClient implementation with no malicious patterns, network exfiltration, credential access, obfuscation, or process spawning.
build/modern/queryClient.js safe This is a standard TanStack Query QueryClient implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
build/modern/queryObserver.cjs safe This is a standard TanStack Query QueryObserver implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, crypto mining, backdoors, or shell execution.
build/modern/queryObserver.js safe No malicious patterns detected; this is the legitimate TanStack Query QueryObserver source file with only normal query observation logic.
build/modern/removable.cjs safe No malicious patterns detected
build/modern/removable.js safe No malicious patterns detected; the file contains legitimate garbage collection scheduling logic for cache entries with no network, filesystem, process, or dynamic code execution concerns.
build/modern/retryer.cjs safe No malicious patterns detected
build/modern/retryer.js safe No malicious patterns detected; this is a standard fetch retry utility with no network exfiltration, process spawning, or dynamic code execution.
build/modern/streamedQuery.cjs safe No malicious patterns detected; the code is a legitimate TanStack Query utility for streaming async iterables with no network, filesystem, process, or dynamic code execution behavior.
build/modern/streamedQuery.js safe No malicious patterns detected; the file implements a standard streamed query helper with no exfiltration, credential harvesting, code execution, or suspicious runtime behavior.
build/modern/subscribable.cjs safe No malicious patterns detected; the file is a straightforward implementation of a subscribable base class from the TanStack Query library with no network, filesystem, process, or dynamic code execution behavior.
build/modern/subscribable.js safe No malicious patterns detected
build/modern/timeoutManager.cjs safe The file is a benign timeout manager from TanStack Query with no malicious behavior, exfiltration, or install-time execution.
build/modern/timeoutManager.js safe No malicious patterns detected; the code is a legitimate timeout manager from TanStack Query with only standard timer delegation and debugging warnings.
build/modern/types.cjs safe No malicious patterns detected
build/modern/types.js safe No malicious patterns detected; the file only defines and exports three Symbol constants and contains a source map reference.
build/modern/utils.cjs safe This is a legitimate utility module from TanStack Query containing only standard helper functions (hashing, deep comparison, timeout handling) with no malicious patterns detected.
build/modern/utils.js safe No malicious patterns detected; the file contains standard TanStack Query utility functions with no network, filesystem, process, credential, or obfuscated code concerns.
src/environmentManager.ts safe Cleared by Jev triage; no further analysis needed
src/focusManager.ts safe Cleared by Jev triage; no further analysis needed
src/hydration.ts safe No malicious patterns detected; this is standard TanStack Query hydration/dehydration code with no data exfiltration, credential harvesting, obfuscation, or process execution.
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/infiniteQueryBehavior.ts safe No malicious patterns detected; the code implements infinite query pagination logic without any data exfiltration, credential harvesting, obfuscation, or other security concerns.
src/infiniteQueryObserver.ts safe Cleared by Jev triage; no further analysis needed
src/mutation.ts safe Cleared by Jev triage; no further analysis needed
src/mutationCache.ts safe Cleared by Jev triage; no further analysis needed
src/mutationObserver.ts safe Cleared by Jev triage; no further analysis needed
src/notifyManager.ts safe Cleared by Jev triage; no further analysis needed
src/onlineManager.ts safe Cleared by Jev triage; no further analysis needed
src/queriesObserver.ts safe This is a standard TanStack Query observer implementation with no malicious patterns, network calls, process spawning, filesystem access, or dynamic code execution.
src/query.ts safe No malicious patterns detected; the file is a standard query cache implementation for TanStack Query with no exfiltration, credential harvesting, obfuscation, or process/network abuse.
src/queryCache.ts safe Cleared by Jev triage; no further analysis needed
src/queryClient.ts safe Cleared by Jev triage; no further analysis needed
src/queryObserver.ts safe Cleared by Jev triage; no further analysis needed
src/removable.ts safe Cleared by Jev triage; no further analysis needed
src/retryer.ts safe Cleared by Jev triage; no further analysis needed
src/streamedQuery.ts safe Cleared by Jev triage; no further analysis needed
src/subscribable.ts safe Cleared by Jev triage; no further analysis needed
src/timeoutManager.ts safe No malicious patterns detected
src/types.ts safe Cleared by Jev triage; no further analysis needed
src/utils.ts safe No malicious patterns detected in this TypeScript utility module from what appears to be a TanStack Query-like library; all code is standard utility functions with no network, filesystem, process, or credential access.

Affected version ranges

None of the 2 scanned versions of @tanstack/query-core are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.50.15.104.1
VersionsVerdictCountRangeTop findings
5.104.1 No issues 1 5.104.1
5.101.2 โ€“ 5.103.2 Not scanned 2 >=5.101.2 <=5.103.2
5.90.12 No issues 1 5.90.12
5.50.1 Not scanned 1 5.50.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @tanstack/query-core

VersionVerdictFilesScanned
5.104.1 No issues 119 Oct 6, 2026
5.90.12 No issues 116 Oct 4, 2026

Frequently asked questions

Is @tanstack/query-core safe to use?

Our AI source review of @tanstack/query-core@5.104.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @tanstack/query-core contain malware?

No malware was identified in @tanstack/query-core@5.104.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @tanstack/query-core checked?

Togoder Security downloaded the published npm package and had an AI model read its 119 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @tanstack/query-core together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tanstack/query-core@5.104.1, cost nothing.

Related security reports