# @tanstack/query-core@5.90.12 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:18:08.000Z
- Files reviewed: 116
- Findings: no findings
- Report: https://security.togoder.click/npm/@tanstack/query-core@5.90.12
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @tanstack/query-core@5.90.12 on Oct 4, 2026. An AI review of 116 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `build/legacy/chunk-PXG64RU4.js` (safe): No malicious patterns detected; the file only contains standard private field access helper functions generated by TypeScript.
- `build/legacy/focusManager.cjs` (safe): No malicious patterns detected; the code is a standard focus manager implementation with no data exfiltration, credential access, obfuscation, or suspicious behaviors.
- `build/legacy/focusManager.js` (safe): No malicious patterns detected; the code is a standard focus manager for React Query's legacy build.
- `build/legacy/hydration.cjs` (safe): No malicious patterns detected; the file contains standard hydration/dehydration logic from TanStack Query with no data exfiltration, credential harvesting, obfuscated code, dynamic execution, or suspicious network/process activity.
- `build/legacy/hydration.js` (safe): No malicious patterns detected
- `build/legacy/index.cjs` (safe): No malicious patterns detected; this is a standard CommonJS bundle re-exporting internal modules with no network, filesystem, or process activity.
- `build/legacy/index.js` (safe): No malicious patterns detected
- `build/legacy/infiniteQueryBehavior.cjs` (safe): This is a legitimate TanStack Query infinite query behavior implementation with no malicious patterns; it only implements client-side pagination logic and signal handling.
- `build/legacy/infiniteQueryBehavior.js` (safe): No malicious patterns detected; the code is a legitimate implementation of infinite query behavior for TanStack Query.
- `build/legacy/infiniteQueryObserver.cjs` (safe): No malicious patterns detected; the file contains standard bundled JavaScript exports for TanStack Query's InfiniteQueryObserver with only benign module system helpers and class definition.
- `build/legacy/infiniteQueryObserver.js` (safe): No malicious patterns detected
- `build/legacy/mutation.cjs` (safe): No malicious patterns detected; the file contains standard JavaScript utilities for a TanStack Query mutation class with no network, filesystem, credential, or code-execution risks.
- `build/legacy/mutation.js` (safe): No malicious patterns detected; the code is a legitimate mutation state manager for the TanStack Query library with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
- `build/legacy/mutationCache.cjs` (safe): No malicious patterns detected; the code is a standard compiled CommonJS build artifact of a mutation cache utility with no network, filesystem, process, or dynamic execution activity.
- `build/legacy/mutationCache.js` (safe): No malicious patterns detected; the code is a standard implementation of a mutation cache from the TanStack Query library.
- `build/legacy/mutationObserver.cjs` (safe): No malicious patterns detected; this is a standard build artifact for a MutationObserver class from the TanStack Query library with no obfuscation, network activity, or credential harvesting.
- `build/legacy/mutationObserver.js` (safe): This is a standard mutation observer implementation from TanStack Query with no malicious patterns, network calls, credential access, or dynamic code execution.
- `build/legacy/notifyManager.cjs` (safe): No malicious patterns detected; the code is a standard notification manager with batching and scheduling utilities from React Query.
- `build/legacy/notifyManager.js` (safe): No malicious patterns detected
- `build/legacy/onlineManager.cjs` (safe): The file contains standard compiler-generated helpers and an online/offline status manager using browser event listeners, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
- `build/legacy/onlineManager.js` (safe): No malicious patterns detected; the code is a standard online/offline manager that listens to browser events and notifies subscribers.
- `build/legacy/queriesObserver.cjs` (safe): No malicious patterns detected; the file is a standard compiled CommonJS module for TanStack Query's QueriesObserver with only benign helper boilerplate and no network, filesystem, process, or dynamic execution activity.
- `build/legacy/queriesObserver.js` (safe): No malicious patterns detected; this is a standard TanStack Query QueriesObserver module with no external exfiltration, dynamic execution, or suspicious behavior.
- `build/legacy/query.cjs` (safe): No malicious patterns detected; the code is a standard build artifact for TanStack Query's core query logic, using only relative imports and no network, filesystem, process, or dynamic code execution.
- `build/legacy/query.js` (safe): This is a legitimate TanStack Query library file with no malicious patterns, network exfiltration, credential harvesting, obfuscation, or process spawning.
- `build/legacy/queryCache.cjs` (safe): No malicious patterns detected; the file contains standard CommonJS build output for a query cache implementation with no network, filesystem, process execution, or obfuscation red flags.
- `build/legacy/queryCache.js` (safe): This is a standard QueryCache implementation from TanStack Query with no malicious patterns, network calls, file system access, or code execution.
- `build/legacy/queryClient.cjs` (safe): No malicious patterns detected; the file is a legitimate build artifact of TanStack Query's QueryClient with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/legacy/queryClient.js` (safe): No malicious patterns detected; the code is a standard TanStack Query QueryClient implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `build/legacy/queryObserver.cjs` (safe): No malicious patterns detected; this is a legitimate TanStack Query QueryObserver module with standard utility and class definitions.
- `build/legacy/queryObserver.js` (safe): This is a legitimate TanStack Query QueryObserver module with no malicious patterns detected.
- `build/legacy/removable.cjs` (safe): No malicious patterns detected
- `build/legacy/removable.js` (safe): No malicious patterns detected
- `build/legacy/retryer.cjs` (safe): No malicious patterns detected
- `build/legacy/retryer.js` (safe): No malicious patterns detected; this is a legitimate retry logic module from TanStack Query with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file operations.
- `build/legacy/streamedQuery.cjs` (safe): No malicious patterns detected; the code is a standard CommonJS build artifact for a streamed query utility with no network, filesystem, or dynamic execution risks.
- `build/legacy/streamedQuery.js` (safe): No malicious patterns detected; the code implements a legitimate streamed query utility for a data-fetching library.
- `build/legacy/subscribable.cjs` (safe): No malicious patterns detected
- `build/legacy/subscribable.js` (safe): The code is a simple event subscription class with no malicious patterns such as network requests, environment access, code execution, or file system manipulation.
- `build/legacy/thenable.cjs` (safe): No malicious patterns detected; the code is a standard thenable utility with no network, filesystem, process, or obfuscation concerns.
- `build/legacy/thenable.js` (safe): The code implements a pending thenable utility with no malicious patterns, external calls, or sensitive data access.
- `build/legacy/timeoutManager.cjs` (safe): No malicious patterns detected; the code is a benign timeout manager utility with standard build wrapper functions.
- `build/legacy/timeoutManager.js` (safe): No malicious patterns detected
- `build/legacy/types.cjs` (safe): No malicious patterns detected
- `build/legacy/types.js` (safe): No malicious patterns detected
- `build/legacy/utils.cjs` (safe): This is a legitimate TanStack Query utility module with no malicious patterns detected; it only contains standard helper functions for query matching, hashing, and data manipulation.
- `build/legacy/utils.js` (safe): No malicious patterns detected; the file contains standard utility functions for TanStack Query.
- `build/modern/focusManager.cjs` (safe): No malicious patterns detected; the code is a standard focus manager using visibilitychange event listeners with no data exfiltration, credential harvesting, or dynamic code execution.
- `build/modern/focusManager.js` (safe): No malicious patterns detected
- `build/modern/hydration.cjs` (safe): No malicious patterns detected; the code is a standard TanStack Query hydration utility with no network, filesystem, process, or obfuscated behavior.
- `build/modern/hydration.js` (safe): No malicious patterns detected; this is standard TanStack Query hydration serialization logic with no data exfiltration, credential harvesting, code execution, or network/file/process abuse.
- `build/modern/index.cjs` (safe): No malicious patterns detected; this is a standard CommonJS bundle re-exporting internal modules with no network, filesystem, or process activity.
- `build/modern/index.js` (safe): This is a standard re-export module from TanStack Query that only imports and exports library components with no malicious patterns detected.
- `build/modern/infiniteQueryBehavior.cjs` (safe): This is a legitimate TanStack Query infinite query behavior module with no malicious patterns, network calls, credential harvesting, or obfuscated code.
- `build/modern/infiniteQueryBehavior.js` (safe): No malicious patterns detected; the code implements infinite query pagination logic for a data-fetching library without any exfiltration, credential harvesting, obfuscation, or process execution.
- `build/modern/infiniteQueryObserver.cjs` (safe): No malicious patterns detected; this is a standard TanStack Query InfiniteQueryObserver build file with only expected imports and class logic.
- `build/modern/infiniteQueryObserver.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/mutation.cjs` (safe): No malicious patterns detected
- `build/modern/mutation.js` (safe): No malicious patterns detected
- `build/modern/mutationCache.cjs` (safe): The code is a standard mutation cache implementation for a JavaScript library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `build/modern/mutationCache.js` (safe): No malicious patterns detected; the code is a standard TanStack Query MutationCache implementation with no network, filesystem, process, or dynamic execution activity.
- `build/modern/mutationObserver.cjs` (safe): This is a transpiled TanStack Query MutationObserver module with no malicious patterns, network calls, credential harvesting, or dynamic code execution.
- `build/modern/mutationObserver.js` (safe): This is a standard TanStack Query MutationObserver implementation with no malicious patterns, network calls, code execution, or file system access.
- `build/modern/notifyManager.cjs` (safe): No malicious patterns detected; the code is a standard notification manager with batching and scheduling utilities from React Query.
- `build/modern/notifyManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/onlineManager.cjs` (safe): This is a standard browser online/offline status manager from TanStack Query; it only registers online/offline event listeners and contains no malicious patterns.
- `build/modern/onlineManager.js` (safe): This is a legitimate online/offline status manager from TanStack Query with no malicious patterns; it only adds standard browser event listeners.
- `build/modern/queriesObserver.cjs` (safe): No malicious patterns detected; the code is a standard CommonJS build of a TanStack Query QueriesObserver with no network, filesystem, process, or dynamic code execution behavior.
- `build/modern/queriesObserver.js` (safe): No malicious patterns detected; the code is a standard TanStack Query observer implementation with no network, credential, or process-related red flags.
- `build/modern/query.cjs` (safe): No malicious patterns detected
- `build/modern/query.js` (safe): No malicious patterns detected; this is standard TanStack Query source code with no exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
- `build/modern/queryCache.cjs` (safe): No malicious patterns detected; this is a standard query cache implementation from TanStack Query.
- `build/modern/queryCache.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/queryClient.cjs` (safe): This is a legitimate TanStack Query QueryClient build artifact with standard class implementation and no malicious patterns, network exfiltration, credential harvesting, obfuscated code, or shell execution.
- `build/modern/queryClient.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/queryObserver.cjs` (safe): No malicious patterns detected; the file is a standard TanStack Query QueryObserver implementation with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity.
- `build/modern/queryObserver.js` (safe): No malicious patterns detected
- `build/modern/removable.cjs` (safe): No malicious patterns detected
- `build/modern/removable.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/retryer.cjs` (safe): No malicious patterns detected; this is a standard retry utility from TanStack Query with no exfiltration, credential harvesting, obfuscation, or process execution.
- `build/modern/retryer.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/streamedQuery.cjs` (safe): No malicious patterns detected; the code is a standard CommonJS build artifact for a streamed query utility with no network, filesystem, or dynamic execution risks.
- `build/modern/streamedQuery.js` (safe): No malicious patterns detected; the code is a benign streaming query utility for a data fetching library.
- `build/modern/subscribable.cjs` (safe): No malicious patterns detected
- `build/modern/subscribable.js` (safe): No malicious patterns detected; this is a simple, benign event subscription utility class with no network, filesystem, process, credential, or dynamic code execution behavior.
- `build/modern/thenable.cjs` (safe): No malicious patterns detected; the code implements standard thenable/promise utilities with no network, filesystem, process, or dynamic execution activity.
- `build/modern/thenable.js` (safe): No malicious patterns detected; the code only implements a synchronous thenable wrapper and sync resolution helper without external communication, credential access, dynamic code execution, or process spawning.
- `build/modern/timeoutManager.cjs` (safe): The code is a legitimate timeout manager utility that wraps global timer functions and does not contain any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `build/modern/timeoutManager.js` (safe): No malicious patterns detected; the code is a straightforward timeout manager with no data exfiltration, credential harvesting, dynamic code execution, filesystem manipulation, or other red flags.
- `build/modern/types.cjs` (safe): No malicious patterns detected
- `build/modern/types.js` (safe): The file only defines and exports three Symbol constants with no executable or suspicious behavior.
- `build/modern/utils.cjs` (safe): No malicious patterns detected
- `build/modern/utils.js` (safe): No malicious patterns detected
- `src/focusManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/hydration.ts` (safe): No malicious patterns detected; this is a standard React Query data dehydration/hydration module with no external network calls, credential access, dynamic code execution, or process spawning.
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/infiniteQueryBehavior.ts` (safe): No malicious patterns detected
- `src/infiniteQueryObserver.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutation.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutationCache.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutationObserver.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/notifyManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/onlineManager.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queriesObserver.ts` (safe): No malicious patterns detected in src/queriesObserver.ts; the code is a legitimate TanStack Query observer implementation with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `src/query.ts` (safe): This is a standard TanStack Query core module with no malicious patterns detected.
- `src/queryCache.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queryClient.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queryObserver.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/removable.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/retryer.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/streamedQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/subscribable.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/thenable.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/timeoutManager.ts` (safe): The code is a legitimate timeout manager implementation for TanStack Query, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or backdoor mechanisms detected.
- `src/types.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils.ts` (safe): No malicious patterns detected; the code is standard TanStack Query utility functions with no exfiltration, credential harvesting, obfuscation, or process execution.

## Version ranges

None of the 2 scanned versions of @tanstack/query-core are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.104.1 (`5.104.1`): clean
- 5.101.2 – 5.103.2 (`>=5.101.2 <=5.103.2`): not scanned
- 5.90.12 (`5.90.12`): clean
- 5.50.1 (`5.50.1`): not scanned

## Scanned versions

- [5.104.1](https://security.togoder.click/npm/@tanstack/query-core@5.104.1): safe, 2026-10-06T14:12:39.000Z
- [5.90.12](https://security.togoder.click/npm/@tanstack/query-core@5.90.12): safe, 2026-10-04T16:18:08.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
