Togoder security

npm package security report

@tanstack/react-query npm package: is it safe?

No malicious code found.

No issues Version 5.104.1 Files reviewed 134 Size 425.3 KB Scanned

Summary

Togoder Security scanned the npm package @tanstack/react-query@5.104.1 on Oct 6, 2026. An AI review of 134 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
build/codemods/utils/index.cjs safe No malicious patterns detected; this is a benign jscodeshift codemod utility for React Query migrations with no network, filesystem, process, or dynamic execution activity.
build/codemods/utils/transformers/query-cache-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/utils/transformers/query-client-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/utils/transformers/use-query-like-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v4/key-transformation.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v4/replace-import-specifier.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v4/utils/replacers/key-replacer.cjs safe No malicious patterns detected; the code is a standard jscodeshift codemod for transforming query key expressions without network, filesystem, or execution abuse.
build/codemods/v5/is-loading/is-loading.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/keep-previous-data/keep-previous-data.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/keep-previous-data/utils/already-has-placeholder-data-property.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/remove-overloads/remove-overloads.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/remove-overloads/transformers/filter-aware-usage-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/remove-overloads/transformers/query-fn-aware-usage-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/remove-overloads/utils/index.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/remove-overloads/utils/unknown-usage-error.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/rename-hydrate/rename-hydrate.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/v5/rename-properties/rename-properties.cjs safe Cleared by Jev triage; no further analysis needed
build/legacy/HydrationBoundary.cjs safe No malicious patterns detected; the file is a legitimate TanStack Query HydrationBoundary implementation with standard React and query hydration logic.
build/legacy/HydrationBoundary.js safe No malicious patterns detected; the code is a legitimate React Query HydrationBoundary implementation using only standard React hooks and internal hydration logic.
build/legacy/IsRestoringProvider.cjs safe No malicious patterns detected
build/legacy/IsRestoringProvider.js safe Cleared by Jev triage; no further analysis needed
build/legacy/QueryClientProvider.cjs safe No malicious patterns detected; this is a standard React context provider implementation from TanStack Query.
build/legacy/QueryClientProvider.js safe No malicious patterns detected; the file is a legitimate React Query provider implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
build/legacy/QueryErrorResetBoundary.cjs safe No malicious patterns detected
build/legacy/QueryErrorResetBoundary.js safe No malicious patterns detected
Show 109 more files
FileVerdictWhat the reviewer saw
build/legacy/errorBoundaryUtils.cjs safe No malicious patterns detected
build/legacy/errorBoundaryUtils.js safe No malicious patterns detected
build/legacy/index.cjs safe This is a standard legacy CommonJS build artifact for TanStack React Query that only re-exports APIs from local modules and @tanstack/query-core with no malicious patterns detected.
build/legacy/index.js safe No malicious patterns detected
build/legacy/infiniteQueryOptions.cjs safe No malicious patterns detected
build/legacy/infiniteQueryOptions.js safe No malicious patterns detected
build/legacy/mutationOptions.cjs safe No malicious patterns detected
build/legacy/mutationOptions.js safe No malicious patterns detected
build/legacy/queryOptions.cjs safe No malicious patterns detected
build/legacy/queryOptions.js safe No malicious patterns detected
build/legacy/rolldown-runtime-VH7oDXx4.cjs safe No malicious patterns detected
build/legacy/suspense.cjs safe No malicious patterns detected
build/legacy/suspense.js safe No malicious patterns detected; the file contains only benign suspense utility logic with no network, filesystem, process, or dynamic code execution activity.
build/legacy/types.cjs safe No malicious patterns detected
build/legacy/types.js safe No malicious patterns detected
build/legacy/useBaseQuery.cjs safe No malicious patterns detected; the code is a standard TanStack Query React hook implementation with no security concerns.
build/legacy/useBaseQuery.js safe No malicious patterns detected; this is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security red flags.
build/legacy/useInfiniteQuery.cjs safe No malicious patterns detected
build/legacy/useInfiniteQuery.js safe No malicious patterns detected; the file is a standard React hook wrapper for TanStack Query's useInfiniteQuery.
build/legacy/useIsFetching.cjs safe No malicious patterns detected
build/legacy/useIsFetching.js safe No malicious patterns detected; this is a standard React Query useIsFetching hook that only uses internal library APIs and React hooks with no network, filesystem, or process operations.
build/legacy/useMutation.cjs safe No malicious patterns detected; the file is a standard TanStack React Query useMutation hook implementation with no exfiltration, obfuscation, process spawning, or filesystem access.
build/legacy/useMutation.js safe This is a standard TanStack React Query useMutation hook implementation with no malicious patterns detected.
build/legacy/useMutationState.cjs safe No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with only expected requires and no obfuscation, network calls, or process execution.
build/legacy/useMutationState.js safe No malicious patterns detected
build/legacy/usePrefetchInfiniteQuery.cjs safe This file contains only legitimate TanStack Query hook implementation with no malicious patterns, network exfiltration, obfuscation, or dynamic code execution.
build/legacy/usePrefetchInfiniteQuery.js safe This is a standard React Query hook implementation with no malicious patterns, external calls, or suspicious behavior detected.
build/legacy/usePrefetchQuery.cjs safe The code is a legitimate TanStack Query React hook implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution.
build/legacy/usePrefetchQuery.js safe No malicious patterns detected
build/legacy/useQueries.cjs safe This is a legitimate TanStack Query React hook implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
build/legacy/useQueries.js safe No malicious patterns detected; this is a legitimate TanStack React Query hook that only performs in-process query management with no network, filesystem, or process access.
build/legacy/useQuery.cjs safe No malicious patterns detected
build/legacy/useQuery.js safe No malicious patterns detected
build/legacy/useSuspenseInfiniteQuery.cjs safe No malicious patterns detected; this is a standard TanStack React Query hook implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/legacy/useSuspenseInfiniteQuery.js safe No malicious patterns detected; the file is a standard TanStack Query React hook implementation with only documentation comments, a NODE_ENV console warning, and calls to local modules.
build/legacy/useSuspenseQueries.cjs safe No malicious patterns detected; the code is a legitimate React Query hook implementation for suspense queries.
build/legacy/useSuspenseQueries.js safe No malicious patterns detected in the analyzed React suspense hook implementation.
build/legacy/useSuspenseQuery.cjs safe No malicious patterns detected
build/legacy/useSuspenseQuery.js safe This is a standard TanStack React Query hook implementation with no malicious patterns, network calls, credential access, dynamic code execution, or process spawning.
build/modern/HydrationBoundary.cjs safe No malicious patterns detected; the file is a legitimate TanStack Query HydrationBoundary implementation with standard React and query hydration logic.
build/modern/HydrationBoundary.js safe No malicious patterns detected; the code is a legitimate React Query HydrationBoundary implementation using only standard React hooks and internal hydration logic.
build/modern/IsRestoringProvider.cjs safe No malicious patterns detected
build/modern/IsRestoringProvider.js safe Cleared by Jev triage; no further analysis needed
build/modern/QueryClientProvider.cjs safe No malicious patterns detected; this is a standard React context provider implementation from TanStack Query.
build/modern/QueryClientProvider.js safe No malicious patterns detected; the file is a legitimate React Query provider implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
build/modern/QueryErrorResetBoundary.cjs safe No malicious patterns detected
build/modern/QueryErrorResetBoundary.js safe No malicious patterns detected
build/modern/errorBoundaryUtils.cjs safe No malicious patterns detected
build/modern/errorBoundaryUtils.js safe No malicious patterns detected
build/modern/index.cjs safe This is a standard legacy CommonJS build artifact for TanStack React Query that only re-exports APIs from local modules and @tanstack/query-core with no malicious patterns detected.
build/modern/index.js safe No malicious patterns detected
build/modern/infiniteQueryOptions.cjs safe No malicious patterns detected
build/modern/infiniteQueryOptions.js safe No malicious patterns detected
build/modern/mutationOptions.cjs safe No malicious patterns detected
build/modern/mutationOptions.js safe No malicious patterns detected
build/modern/queryOptions.cjs safe No malicious patterns detected
build/modern/queryOptions.js safe No malicious patterns detected
build/modern/rolldown-runtime-VH7oDXx4.cjs safe No malicious patterns detected
build/modern/suspense.cjs safe No malicious patterns detected; the file contains normal React Query suspense logic with no network, filesystem, process, or dynamic execution activity.
build/modern/suspense.js safe No malicious patterns detected
build/modern/types.cjs safe No malicious patterns detected
build/modern/types.js safe No malicious patterns detected
build/modern/useBaseQuery.cjs safe No malicious patterns detected; the code is a standard TanStack Query React hook implementation with no security concerns.
build/modern/useBaseQuery.js safe No malicious patterns detected; this is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security red flags.
build/modern/useInfiniteQuery.cjs safe No malicious patterns detected
build/modern/useInfiniteQuery.js safe No malicious patterns detected; the file is a standard React hook wrapper for TanStack Query's useInfiniteQuery.
build/modern/useIsFetching.cjs safe No malicious patterns detected
build/modern/useIsFetching.js safe No malicious patterns detected; this is a standard React Query useIsFetching hook that only uses internal library APIs and React hooks with no network, filesystem, or process operations.
build/modern/useMutation.cjs safe No malicious patterns detected; the file is a standard TanStack React Query useMutation hook implementation with no exfiltration, obfuscation, process spawning, or filesystem access.
build/modern/useMutation.js safe This is a standard TanStack React Query useMutation hook implementation with no malicious patterns detected.
build/modern/useMutationState.cjs safe No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with only expected requires and no obfuscation, network calls, or process execution.
build/modern/useMutationState.js safe No malicious patterns detected
build/modern/usePrefetchInfiniteQuery.cjs safe This file contains only legitimate TanStack Query hook implementation with no malicious patterns, network exfiltration, obfuscation, or dynamic code execution.
build/modern/usePrefetchInfiniteQuery.js safe This is a standard React Query hook implementation with no malicious patterns, external calls, or suspicious behavior detected.
build/modern/usePrefetchQuery.cjs safe The code is a legitimate TanStack Query React hook implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution.
build/modern/usePrefetchQuery.js safe No malicious patterns detected
build/modern/useQueries.cjs safe This is a legitimate TanStack Query React hook implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
build/modern/useQueries.js safe No malicious patterns detected; this is a legitimate TanStack React Query hook that only performs in-process query management with no network, filesystem, or process access.
build/modern/useQuery.cjs safe No malicious patterns detected
build/modern/useQuery.js safe No malicious patterns detected
build/modern/useSuspenseInfiniteQuery.cjs safe No malicious patterns detected; this is a standard TanStack React Query hook implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/modern/useSuspenseInfiniteQuery.js safe No malicious patterns detected; the file is a standard TanStack Query React hook implementation with only documentation comments, a NODE_ENV console warning, and calls to local modules.
build/modern/useSuspenseQueries.cjs safe No malicious patterns detected; the code is a legitimate React Query hook implementation for suspense queries.
build/modern/useSuspenseQueries.js safe No malicious patterns detected in the analyzed React suspense hook implementation.
build/modern/useSuspenseQuery.cjs safe No malicious patterns detected
build/modern/useSuspenseQuery.js safe This is a standard TanStack React Query hook implementation with no malicious patterns, network calls, credential access, dynamic code execution, or process spawning.
src/HydrationBoundary.tsx safe Cleared by Jev triage; no further analysis needed
src/IsRestoringProvider.ts safe Cleared by Jev triage; no further analysis needed
src/QueryClientProvider.tsx safe Cleared by Jev triage; no further analysis needed
src/QueryErrorResetBoundary.tsx safe Cleared by Jev triage; no further analysis needed
src/errorBoundaryUtils.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/infiniteQueryOptions.ts safe Cleared by Jev triage; no further analysis needed
src/mutationOptions.ts safe Cleared by Jev triage; no further analysis needed
src/queryOptions.ts safe Cleared by Jev triage; no further analysis needed
src/suspense.ts safe Cleared by Jev triage; no further analysis needed
src/types.ts safe Cleared by Jev triage; no further analysis needed
src/useBaseQuery.ts safe No malicious patterns detected
src/useInfiniteQuery.ts safe Cleared by Jev triage; no further analysis needed
src/useIsFetching.ts safe Cleared by Jev triage; no further analysis needed
src/useMutation.ts safe Cleared by Jev triage; no further analysis needed
src/useMutationState.ts safe Cleared by Jev triage; no further analysis needed
src/usePrefetchInfiniteQuery.tsx safe No malicious patterns detected; the file is a legitimate React hook that prefetches infinite query data via the TanStack Query client without any network, filesystem, process, or dynamic code execution behavior.
src/usePrefetchQuery.tsx safe No malicious patterns detected; the code is a straightforward React hook wrapper around TanStack Query's prefetch functionality.
src/useQueries.ts safe Cleared by Jev triage; no further analysis needed
src/useQuery.ts safe Cleared by Jev triage; no further analysis needed
src/useSuspenseInfiniteQuery.ts safe No malicious patterns detected
src/useSuspenseQueries.ts safe This is a legitimate TanStack React Query hook implementation with no malicious patterns, network exfiltration, process spawning, or dynamic code execution.
src/useSuspenseQuery.ts safe This is a legitimate React Query Suspense hook implementation with no malicious patterns, obfuscation, network exfiltration, or dangerous code execution.

Affected version ranges

None of the 2 scanned versions of @tanstack/react-query are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.50.15.104.1
VersionsVerdictCountRangeTop findings
5.104.1 No issues 1 5.104.1
5.101.2 โ€“ 5.103.2 Not scanned 2 >=5.101.2 <=5.103.2
5.90.12 No issues 1 5.90.12
5.50.1 Not scanned 1 5.50.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @tanstack/react-query

VersionVerdictFilesScanned
5.104.1 No issues 134 Oct 6, 2026
5.90.12 No issues 135 Oct 4, 2026

Frequently asked questions

Is @tanstack/react-query safe to use?

Our AI source review of @tanstack/react-query@5.104.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @tanstack/react-query contain malware?

No malware was identified in @tanstack/react-query@5.104.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @tanstack/react-query checked?

Togoder Security downloaded the published npm package and had an AI model read its 134 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @tanstack/react-query together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tanstack/react-query@5.104.1, cost nothing.

Related security reports