# @tanstack/react-query@5.104.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:12:47.000Z
- Files reviewed: 134
- Findings: no findings
- Report: https://security.togoder.click/npm/@tanstack/react-query@5.104.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @tanstack/react-query@5.104.1 on Oct 6, 2026. An AI review of 134 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `build/codemods/utils/index.cjs` (safe): No malicious patterns detected; this is a benign jscodeshift codemod utility for React Query migrations with no network, filesystem, process, or dynamic execution activity.
- `build/codemods/utils/transformers/query-cache-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/utils/transformers/query-client-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/utils/transformers/use-query-like-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v4/key-transformation.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v4/replace-import-specifier.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v4/utils/replacers/key-replacer.cjs` (safe): No malicious patterns detected; the code is a standard jscodeshift codemod for transforming query key expressions without network, filesystem, or execution abuse.
- `build/codemods/v5/is-loading/is-loading.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/keep-previous-data/keep-previous-data.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/keep-previous-data/utils/already-has-placeholder-data-property.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/remove-overloads/remove-overloads.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/remove-overloads/transformers/filter-aware-usage-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/remove-overloads/transformers/query-fn-aware-usage-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/remove-overloads/utils/index.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/remove-overloads/utils/unknown-usage-error.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/rename-hydrate/rename-hydrate.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/v5/rename-properties/rename-properties.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/legacy/HydrationBoundary.cjs` (safe): No malicious patterns detected; the file is a legitimate TanStack Query HydrationBoundary implementation with standard React and query hydration logic.
- `build/legacy/HydrationBoundary.js` (safe): No malicious patterns detected; the code is a legitimate React Query HydrationBoundary implementation using only standard React hooks and internal hydration logic.
- `build/legacy/IsRestoringProvider.cjs` (safe): No malicious patterns detected
- `build/legacy/IsRestoringProvider.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/legacy/QueryClientProvider.cjs` (safe): No malicious patterns detected; this is a standard React context provider implementation from TanStack Query.
- `build/legacy/QueryClientProvider.js` (safe): No malicious patterns detected; the file is a legitimate React Query provider implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `build/legacy/QueryErrorResetBoundary.cjs` (safe): No malicious patterns detected
- `build/legacy/QueryErrorResetBoundary.js` (safe): No malicious patterns detected
- `build/legacy/errorBoundaryUtils.cjs` (safe): No malicious patterns detected
- `build/legacy/errorBoundaryUtils.js` (safe): No malicious patterns detected
- `build/legacy/index.cjs` (safe): This is a standard legacy CommonJS build artifact for TanStack React Query that only re-exports APIs from local modules and @tanstack/query-core with no malicious patterns detected.
- `build/legacy/index.js` (safe): No malicious patterns detected
- `build/legacy/infiniteQueryOptions.cjs` (safe): No malicious patterns detected
- `build/legacy/infiniteQueryOptions.js` (safe): No malicious patterns detected
- `build/legacy/mutationOptions.cjs` (safe): No malicious patterns detected
- `build/legacy/mutationOptions.js` (safe): No malicious patterns detected
- `build/legacy/queryOptions.cjs` (safe): No malicious patterns detected
- `build/legacy/queryOptions.js` (safe): No malicious patterns detected
- `build/legacy/rolldown-runtime-VH7oDXx4.cjs` (safe): No malicious patterns detected
- `build/legacy/suspense.cjs` (safe): No malicious patterns detected
- `build/legacy/suspense.js` (safe): No malicious patterns detected; the file contains only benign suspense utility logic with no network, filesystem, process, or dynamic code execution activity.
- `build/legacy/types.cjs` (safe): No malicious patterns detected
- `build/legacy/types.js` (safe): No malicious patterns detected
- `build/legacy/useBaseQuery.cjs` (safe): No malicious patterns detected; the code is a standard TanStack Query React hook implementation with no security concerns.
- `build/legacy/useBaseQuery.js` (safe): No malicious patterns detected; this is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security red flags.
- `build/legacy/useInfiniteQuery.cjs` (safe): No malicious patterns detected
- `build/legacy/useInfiniteQuery.js` (safe): No malicious patterns detected; the file is a standard React hook wrapper for TanStack Query's useInfiniteQuery.
- `build/legacy/useIsFetching.cjs` (safe): No malicious patterns detected
- `build/legacy/useIsFetching.js` (safe): No malicious patterns detected; this is a standard React Query useIsFetching hook that only uses internal library APIs and React hooks with no network, filesystem, or process operations.
- `build/legacy/useMutation.cjs` (safe): No malicious patterns detected; the file is a standard TanStack React Query useMutation hook implementation with no exfiltration, obfuscation, process spawning, or filesystem access.
- `build/legacy/useMutation.js` (safe): This is a standard TanStack React Query useMutation hook implementation with no malicious patterns detected.
- `build/legacy/useMutationState.cjs` (safe): No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with only expected requires and no obfuscation, network calls, or process execution.
- `build/legacy/useMutationState.js` (safe): No malicious patterns detected
- `build/legacy/usePrefetchInfiniteQuery.cjs` (safe): This file contains only legitimate TanStack Query hook implementation with no malicious patterns, network exfiltration, obfuscation, or dynamic code execution.
- `build/legacy/usePrefetchInfiniteQuery.js` (safe): This is a standard React Query hook implementation with no malicious patterns, external calls, or suspicious behavior detected.
- `build/legacy/usePrefetchQuery.cjs` (safe): The code is a legitimate TanStack Query React hook implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution.
- `build/legacy/usePrefetchQuery.js` (safe): No malicious patterns detected
- `build/legacy/useQueries.cjs` (safe): This is a legitimate TanStack Query React hook implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `build/legacy/useQueries.js` (safe): No malicious patterns detected; this is a legitimate TanStack React Query hook that only performs in-process query management with no network, filesystem, or process access.
- `build/legacy/useQuery.cjs` (safe): No malicious patterns detected
- `build/legacy/useQuery.js` (safe): No malicious patterns detected
- `build/legacy/useSuspenseInfiniteQuery.cjs` (safe): No malicious patterns detected; this is a standard TanStack React Query hook implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/legacy/useSuspenseInfiniteQuery.js` (safe): No malicious patterns detected; the file is a standard TanStack Query React hook implementation with only documentation comments, a NODE_ENV console warning, and calls to local modules.
- `build/legacy/useSuspenseQueries.cjs` (safe): No malicious patterns detected; the code is a legitimate React Query hook implementation for suspense queries.
- `build/legacy/useSuspenseQueries.js` (safe): No malicious patterns detected in the analyzed React suspense hook implementation.
- `build/legacy/useSuspenseQuery.cjs` (safe): No malicious patterns detected
- `build/legacy/useSuspenseQuery.js` (safe): This is a standard TanStack React Query hook implementation with no malicious patterns, network calls, credential access, dynamic code execution, or process spawning.
- `build/modern/HydrationBoundary.cjs` (safe): No malicious patterns detected; the file is a legitimate TanStack Query HydrationBoundary implementation with standard React and query hydration logic.
- `build/modern/HydrationBoundary.js` (safe): No malicious patterns detected; the code is a legitimate React Query HydrationBoundary implementation using only standard React hooks and internal hydration logic.
- `build/modern/IsRestoringProvider.cjs` (safe): No malicious patterns detected
- `build/modern/IsRestoringProvider.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/modern/QueryClientProvider.cjs` (safe): No malicious patterns detected; this is a standard React context provider implementation from TanStack Query.
- `build/modern/QueryClientProvider.js` (safe): No malicious patterns detected; the file is a legitimate React Query provider implementation with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `build/modern/QueryErrorResetBoundary.cjs` (safe): No malicious patterns detected
- `build/modern/QueryErrorResetBoundary.js` (safe): No malicious patterns detected
- `build/modern/errorBoundaryUtils.cjs` (safe): No malicious patterns detected
- `build/modern/errorBoundaryUtils.js` (safe): No malicious patterns detected
- `build/modern/index.cjs` (safe): This is a standard legacy CommonJS build artifact for TanStack React Query that only re-exports APIs from local modules and @tanstack/query-core with no malicious patterns detected.
- `build/modern/index.js` (safe): No malicious patterns detected
- `build/modern/infiniteQueryOptions.cjs` (safe): No malicious patterns detected
- `build/modern/infiniteQueryOptions.js` (safe): No malicious patterns detected
- `build/modern/mutationOptions.cjs` (safe): No malicious patterns detected
- `build/modern/mutationOptions.js` (safe): No malicious patterns detected
- `build/modern/queryOptions.cjs` (safe): No malicious patterns detected
- `build/modern/queryOptions.js` (safe): No malicious patterns detected
- `build/modern/rolldown-runtime-VH7oDXx4.cjs` (safe): No malicious patterns detected
- `build/modern/suspense.cjs` (safe): No malicious patterns detected; the file contains normal React Query suspense logic with no network, filesystem, process, or dynamic execution activity.
- `build/modern/suspense.js` (safe): No malicious patterns detected
- `build/modern/types.cjs` (safe): No malicious patterns detected
- `build/modern/types.js` (safe): No malicious patterns detected
- `build/modern/useBaseQuery.cjs` (safe): No malicious patterns detected; the code is a standard TanStack Query React hook implementation with no security concerns.
- `build/modern/useBaseQuery.js` (safe): No malicious patterns detected; this is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security red flags.
- `build/modern/useInfiniteQuery.cjs` (safe): No malicious patterns detected
- `build/modern/useInfiniteQuery.js` (safe): No malicious patterns detected; the file is a standard React hook wrapper for TanStack Query's useInfiniteQuery.
- `build/modern/useIsFetching.cjs` (safe): No malicious patterns detected
- `build/modern/useIsFetching.js` (safe): No malicious patterns detected; this is a standard React Query useIsFetching hook that only uses internal library APIs and React hooks with no network, filesystem, or process operations.
- `build/modern/useMutation.cjs` (safe): No malicious patterns detected; the file is a standard TanStack React Query useMutation hook implementation with no exfiltration, obfuscation, process spawning, or filesystem access.
- `build/modern/useMutation.js` (safe): This is a standard TanStack React Query useMutation hook implementation with no malicious patterns detected.
- `build/modern/useMutationState.cjs` (safe): No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with only expected requires and no obfuscation, network calls, or process execution.
- `build/modern/useMutationState.js` (safe): No malicious patterns detected
- `build/modern/usePrefetchInfiniteQuery.cjs` (safe): This file contains only legitimate TanStack Query hook implementation with no malicious patterns, network exfiltration, obfuscation, or dynamic code execution.
- `build/modern/usePrefetchInfiniteQuery.js` (safe): This is a standard React Query hook implementation with no malicious patterns, external calls, or suspicious behavior detected.
- `build/modern/usePrefetchQuery.cjs` (safe): The code is a legitimate TanStack Query React hook implementation with no malicious patterns, external data transmission, credential harvesting, or dynamic code execution.
- `build/modern/usePrefetchQuery.js` (safe): No malicious patterns detected
- `build/modern/useQueries.cjs` (safe): This is a legitimate TanStack Query React hook implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `build/modern/useQueries.js` (safe): No malicious patterns detected; this is a legitimate TanStack React Query hook that only performs in-process query management with no network, filesystem, or process access.
- `build/modern/useQuery.cjs` (safe): No malicious patterns detected
- `build/modern/useQuery.js` (safe): No malicious patterns detected
- `build/modern/useSuspenseInfiniteQuery.cjs` (safe): No malicious patterns detected; this is a standard TanStack React Query hook implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/modern/useSuspenseInfiniteQuery.js` (safe): No malicious patterns detected; the file is a standard TanStack Query React hook implementation with only documentation comments, a NODE_ENV console warning, and calls to local modules.
- `build/modern/useSuspenseQueries.cjs` (safe): No malicious patterns detected; the code is a legitimate React Query hook implementation for suspense queries.
- `build/modern/useSuspenseQueries.js` (safe): No malicious patterns detected in the analyzed React suspense hook implementation.
- `build/modern/useSuspenseQuery.cjs` (safe): No malicious patterns detected
- `build/modern/useSuspenseQuery.js` (safe): This is a standard TanStack React Query hook implementation with no malicious patterns, network calls, credential access, dynamic code execution, or process spawning.
- `src/HydrationBoundary.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/IsRestoringProvider.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/QueryClientProvider.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/QueryErrorResetBoundary.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/errorBoundaryUtils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/infiniteQueryOptions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutationOptions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queryOptions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/suspense.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/types.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useBaseQuery.ts` (safe): No malicious patterns detected
- `src/useInfiniteQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useIsFetching.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useMutation.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useMutationState.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/usePrefetchInfiniteQuery.tsx` (safe): No malicious patterns detected; the file is a legitimate React hook that prefetches infinite query data via the TanStack Query client without any network, filesystem, process, or dynamic code execution behavior.
- `src/usePrefetchQuery.tsx` (safe): No malicious patterns detected; the code is a straightforward React hook wrapper around TanStack Query's prefetch functionality.
- `src/useQueries.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useSuspenseInfiniteQuery.ts` (safe): No malicious patterns detected
- `src/useSuspenseQueries.ts` (safe): This is a legitimate TanStack React Query hook implementation with no malicious patterns, network exfiltration, process spawning, or dynamic code execution.
- `src/useSuspenseQuery.ts` (safe): This is a legitimate React Query Suspense hook implementation with no malicious patterns, obfuscation, network exfiltration, or dangerous code execution.

## Version ranges

None of the 2 scanned versions of @tanstack/react-query are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.104.1 (`5.104.1`): clean
- 5.101.2 – 5.103.2 (`>=5.101.2 <=5.103.2`): not scanned
- 5.90.12 (`5.90.12`): clean
- 5.50.1 (`5.50.1`): not scanned

## Scanned versions

- [5.104.1](https://security.togoder.click/npm/@tanstack/react-query@5.104.1): safe, 2026-10-06T14:12:47.000Z
- [5.90.12](https://security.togoder.click/npm/@tanstack/react-query@5.90.12): safe, 2026-10-04T16:18:18.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
