# @tanstack/query-core@5.104.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:12:39.000Z
- Files reviewed: 119
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@tanstack/query-core@5.104.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @tanstack/query-core@5.104.1 on Oct 6, 2026. An AI review of 119 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic code execution

Finding ID: `NPS-9B474C47B287`

File: `build/modern/timeoutManager.cjs`

This is a wrapper for the platform's setTimeout/setInterval APIs. No eval, Function constructors, or other dynamic execution is present.

## Files reviewed

- `build/legacy/classPrivateFieldSet2-CukOTU3U.js` (safe): This file contains only standard JavaScript private class field helper functions generated by the Oxc runtime, with no network, filesystem, process, credential, or dynamic execution behavior.
- `build/legacy/classPrivateFieldSet2-CvCEk6bM.cjs` (safe): No malicious patterns detected; the file contains standard OXC runtime helper functions for private class field handling with no network, filesystem, process, or obfuscated code.
- `build/legacy/classPrivateMethodInitSpec-CgB-WYk3.js` (safe): This is a standard JavaScript class private method initialization helper with no malicious patterns detected.
- `build/legacy/classPrivateMethodInitSpec-Nr6mgZRs.cjs` (safe): No malicious patterns detected
- `build/legacy/environmentManager.cjs` (safe): No malicious patterns detected; the code only implements a simple, documented environment detection toggle for TanStack Query.
- `build/legacy/environmentManager.js` (safe): No malicious patterns detected
- `build/legacy/focusManager.cjs` (safe): No malicious patterns detected; the code is a legitimate TanStack Query FocusManager implementation with only standard browser event handling.
- `build/legacy/focusManager.js` (safe): No malicious patterns detected; the code is a legitimate focus manager from TanStack Query with only browser visibility event listeners and no network, filesystem, or process operations.
- `build/legacy/hydration.cjs` (safe): No malicious patterns detected; the code is standard TanStack Query hydration/dehydration logic with no exfiltration, credential access, obfuscation, or process spawning.
- `build/legacy/hydration.js` (safe): No malicious patterns detected
- `build/legacy/index.cjs` (safe): No malicious patterns detected; this is a standard barrel index file re-exporting TanStack Query modules.
- `build/legacy/index.js` (safe): No malicious patterns detected; the file is a clean re-export barrel for TanStack Query's legacy build.
- `build/legacy/infiniteQueryBehavior.cjs` (safe): No malicious patterns detected
- `build/legacy/infiniteQueryBehavior.js` (safe): No malicious patterns detected
- `build/legacy/infiniteQueryObserver.cjs` (safe): No malicious patterns detected; the code is a standard TanStack Query InfiniteQueryObserver implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/legacy/infiniteQueryObserver.js` (safe): This is a legitimate TanStack Query InfiniteQueryObserver implementation with no malicious patterns, network calls, file system access, or dynamic code execution.
- `build/legacy/mutation.cjs` (safe): No malicious patterns detected; the code is a standard TanStack Query Mutation class implementation with no exfiltration, obfuscation, or process execution.
- `build/legacy/mutation.js` (safe): This is a legitimate TanStack Query Mutation implementation with no malicious patterns detected
- `build/legacy/mutationCache.cjs` (safe): No malicious patterns detected; the code implements a standard mutation cache for TanStack Query with no network, filesystem, process, or dynamic-eval activity.
- `build/legacy/mutationCache.js` (safe): No malicious patterns detected
- `build/legacy/mutationObserver.cjs` (safe): No malicious patterns detected; this is a standard TanStack Query MutationObserver module with no exfiltration, obfuscation, or process execution code.
- `build/legacy/mutationObserver.js` (safe): This is a legitimate TanStack Query MutationObserver implementation with no malicious patterns detected.
- `build/legacy/notifyManager.cjs` (safe): This file implements a legitimate notify/batching manager for TanStack Query with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `build/legacy/notifyManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/legacy/onlineManager.cjs` (safe): No malicious patterns detected; the file is a standard TanStack Query online manager utility with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `build/legacy/onlineManager.js` (safe): No malicious patterns detected; the file is a standard TanStack Query online state manager using browser online/offline events.
- `build/legacy/queriesObserver.cjs` (safe): This is a legitimate TanStack Query QueriesObserver implementation with no malicious patterns, network calls, dynamic code execution, or credential access.
- `build/legacy/queriesObserver.js` (safe): No malicious patterns detected; the file is a legitimate build artifact of TanStack Query's QueriesObserver with no exfiltration, obfuscation, dynamic execution, or suspicious I/O.
- `build/legacy/query.cjs` (safe): This is a legitimate TanStack Query library file containing only query state management logic with no malicious patterns.
- `build/legacy/query.js` (safe): This is the standard TanStack Query core query implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution detected.
- `build/legacy/queryCache.cjs` (safe): No malicious patterns detected; this is the legitimate TanStack Query QueryCache implementation with only local imports and standard cache management logic.
- `build/legacy/queryCache.js` (safe): This is a legitimate TanStack Query QueryCache implementation with no malicious patterns, network calls, credential harvesting, or dynamic code execution.
- `build/legacy/queryClient.cjs` (safe): No malicious patterns detected
- `build/legacy/queryClient.js` (safe): No malicious patterns detected; this is a legitimate TanStack Query QueryClient implementation with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `build/legacy/queryObserver.cjs` (safe): No malicious patterns detected; this is a legitimate TanStack Query QueryObserver implementation with standard observability, timing, and query management logic.
- `build/legacy/queryObserver.js` (safe): This is a legitimate build artifact of TanStack Query's QueryObserver class; no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution were detected.
- `build/legacy/removable.cjs` (safe): No malicious patterns detected; the code is a standard garbage-collection timer utility for cache entries with no network, filesystem, process, or dynamic code execution activity.
- `build/legacy/removable.js` (safe): No malicious patterns detected; the code is a straightforward garbage collection timer utility with standard imports and no network, filesystem, process, or dynamic execution activity.
- `build/legacy/retryer.cjs` (safe): The code is a legitimate retry utility for TanStack Query with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `build/legacy/retryer.js` (safe): No malicious patterns detected; the code implements a standard retry utility for async operations with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `build/legacy/streamedQuery.cjs` (safe): No malicious patterns detected; the code is a legitimate TanStack Query utility for streaming async iterables with no network, filesystem, process, or dynamic code execution behavior.
- `build/legacy/streamedQuery.js` (safe): No malicious patterns detected; the file implements a standard streamed query helper with no exfiltration, credential harvesting, code execution, or suspicious runtime behavior.
- `build/legacy/subscribable.cjs` (safe): No malicious patterns detected; the file is a straightforward implementation of a subscribable base class from the TanStack Query library with no network, filesystem, process, or dynamic code execution behavior.
- `build/legacy/subscribable.js` (safe): No malicious patterns detected
- `build/legacy/timeoutManager.cjs` (safe): This is legitimate TanStack Query timeout management code with no malicious patterns detected.
- `build/legacy/timeoutManager.js` (safe): No malicious patterns detected
- `build/legacy/types.cjs` (safe): No malicious patterns detected
- `build/legacy/types.js` (safe): No malicious patterns detected; the file only defines and exports three Symbol constants and contains a source map reference.
- `build/legacy/utils.cjs` (safe): No malicious patterns detected
- `build/legacy/utils.js` (safe): No malicious patterns detected
- `build/modern/environmentManager.cjs` (safe): No malicious patterns detected; the code only implements a simple, documented environment detection toggle for TanStack Query.
- `build/modern/environmentManager.js` (safe): No malicious patterns detected
- `build/modern/focusManager.cjs` (safe): No malicious patterns detected; the code is a standard FocusManager utility for TanStack Query that manages browser focus/visibility state without any security concerns.
- `build/modern/focusManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/hydration.cjs` (safe): No malicious patterns detected; the file contains standard TanStack Query hydration/dehydration logic with no network, filesystem, process, or dynamic execution abuse.
- `build/modern/hydration.js` (safe): No malicious patterns detected; the code implements standard TanStack Query hydration/dehydration logic for serializing and restoring query cache state without any exfiltration, credential harvesting, obfuscation, or process execution.
- `build/modern/index.cjs` (safe): No malicious patterns detected; this is a standard barrel index file re-exporting TanStack Query modules.
- `build/modern/index.js` (safe): No malicious patterns detected; the file is a clean re-export barrel for TanStack Query's legacy build.
- `build/modern/infiniteQueryBehavior.cjs` (safe): No malicious patterns detected; the code is a legitimate TanStack Query infinite query behavior implementation with no network, filesystem, process, or dynamic execution concerns.
- `build/modern/infiniteQueryBehavior.js` (safe): No malicious patterns detected; the code is a legitimate TanStack Query infinite query behavior implementation.
- `build/modern/infiniteQueryObserver.cjs` (safe): No malicious patterns detected
- `build/modern/infiniteQueryObserver.js` (safe): No malicious patterns detected; the file is a standard TanStack Query InfiniteQueryObserver implementation with no exfiltration, credential harvesting, dynamic code execution, or other red flags.
- `build/modern/mutation.cjs` (safe): No malicious patterns detected; this is standard TanStack Query mutation lifecycle code with no network exfiltration, credential harvesting, obfuscation, or process spawning.
- `build/modern/mutation.js` (safe): This is legitimate TanStack Query mutation logic with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `build/modern/mutationCache.cjs` (safe): No malicious patterns detected; the code implements a standard MutationCache class for a query library with no network, filesystem, process, or dynamic execution behavior.
- `build/modern/mutationCache.js` (safe): No malicious patterns detected; the file is a standard MutationCache implementation from TanStack Query with no network, filesystem, process, or dynamic code execution concerns.
- `build/modern/mutationObserver.cjs` (safe): No malicious patterns detected
- `build/modern/mutationObserver.js` (safe): No malicious patterns detected; the code is a standard TanStack Query MutationObserver implementation with no exfiltration, credential harvesting, obfuscation, or process execution.
- `build/modern/notifyManager.cjs` (safe): This file implements a legitimate notify/batching manager for TanStack Query with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `build/modern/notifyManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/onlineManager.cjs` (safe): No malicious patterns detected; the file is a benign implementation of TanStack Query's OnlineManager that only registers online/offline event listeners on the window object.
- `build/modern/onlineManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/queriesObserver.cjs` (safe): No malicious patterns detected; this is a legitimate TanStack Query QueriesObserver module with standard require imports and no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `build/modern/queriesObserver.js` (safe): This is a legitimate QueriesObserver implementation from TanStack Query with no malicious patterns detected.
- `build/modern/query.cjs` (safe): No malicious patterns detected; this is legitimate TanStack Query library code with no exfiltration, obfuscation, credential harvesting, or process execution.
- `build/modern/query.js` (safe): This is a legitimate TanStack Query core module with no malicious patterns detected
- `build/modern/queryCache.cjs` (safe): No malicious patterns detected
- `build/modern/queryCache.js` (safe): This is the legitimate QueryCache source from TanStack Query with no malicious patterns, network exfiltration, credential access, dynamic code execution, or unsafe process/file operations.
- `build/modern/queryClient.cjs` (safe): This is the standard TanStack QueryClient implementation with no malicious patterns, network exfiltration, credential access, obfuscation, or process spawning.
- `build/modern/queryClient.js` (safe): This is a standard TanStack Query QueryClient implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `build/modern/queryObserver.cjs` (safe): This is a standard TanStack Query QueryObserver implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, crypto mining, backdoors, or shell execution.
- `build/modern/queryObserver.js` (safe): No malicious patterns detected; this is the legitimate TanStack Query QueryObserver source file with only normal query observation logic.
- `build/modern/removable.cjs` (safe): No malicious patterns detected
- `build/modern/removable.js` (safe): No malicious patterns detected; the file contains legitimate garbage collection scheduling logic for cache entries with no network, filesystem, process, or dynamic code execution concerns.
- `build/modern/retryer.cjs` (safe): No malicious patterns detected
- `build/modern/retryer.js` (safe): No malicious patterns detected; this is a standard fetch retry utility with no network exfiltration, process spawning, or dynamic code execution.
- `build/modern/streamedQuery.cjs` (safe): No malicious patterns detected; the code is a legitimate TanStack Query utility for streaming async iterables with no network, filesystem, process, or dynamic code execution behavior.
- `build/modern/streamedQuery.js` (safe): No malicious patterns detected; the file implements a standard streamed query helper with no exfiltration, credential harvesting, code execution, or suspicious runtime behavior.
- `build/modern/subscribable.cjs` (safe): No malicious patterns detected; the file is a straightforward implementation of a subscribable base class from the TanStack Query library with no network, filesystem, process, or dynamic code execution behavior.
- `build/modern/subscribable.js` (safe): No malicious patterns detected
- `build/modern/timeoutManager.cjs` (safe): The file is a benign timeout manager from TanStack Query with no malicious behavior, exfiltration, or install-time execution.
- `build/modern/timeoutManager.js` (safe): No malicious patterns detected; the code is a legitimate timeout manager from TanStack Query with only standard timer delegation and debugging warnings.
- `build/modern/types.cjs` (safe): No malicious patterns detected
- `build/modern/types.js` (safe): No malicious patterns detected; the file only defines and exports three Symbol constants and contains a source map reference.
- `build/modern/utils.cjs` (safe): This is a legitimate utility module from TanStack Query containing only standard helper functions (hashing, deep comparison, timeout handling) with no malicious patterns detected.
- `build/modern/utils.js` (safe): No malicious patterns detected; the file contains standard TanStack Query utility functions with no network, filesystem, process, credential, or obfuscated code concerns.
- `src/environmentManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/focusManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/hydration.ts` (safe): No malicious patterns detected; this is standard TanStack Query hydration/dehydration code with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/infiniteQueryBehavior.ts` (safe): No malicious patterns detected; the code implements infinite query pagination logic without any data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `src/infiniteQueryObserver.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutation.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutationCache.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutationObserver.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/notifyManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/onlineManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queriesObserver.ts` (safe): This is a standard TanStack Query observer implementation with no malicious patterns, network calls, process spawning, filesystem access, or dynamic code execution.
- `src/query.ts` (safe): No malicious patterns detected; the file is a standard query cache implementation for TanStack Query with no exfiltration, credential harvesting, obfuscation, or process/network abuse.
- `src/queryCache.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queryClient.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queryObserver.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/removable.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/retryer.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/streamedQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/subscribable.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/timeoutManager.ts` (safe): No malicious patterns detected
- `src/types.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils.ts` (safe): No malicious patterns detected in this TypeScript utility module from what appears to be a TanStack Query-like library; all code is standard utility functions with no network, filesystem, process, or credential access.

## Version ranges

None of the 2 scanned versions of @tanstack/query-core are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.104.1 (`5.104.1`): clean
- 5.101.2 – 5.103.2 (`>=5.101.2 <=5.103.2`): not scanned
- 5.90.12 (`5.90.12`): clean
- 5.50.1 (`5.50.1`): not scanned

## Scanned versions

- [5.104.1](https://security.togoder.click/npm/@tanstack/query-core@5.104.1): safe, 2026-10-06T14:12:39.000Z
- [5.90.12](https://security.togoder.click/npm/@tanstack/query-core@5.90.12): safe, 2026-10-04T16:18:08.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
