Togoder security

npm package security report

@tanstack/react-query@5.90.12 security report

No malicious code found.

No issues Version 5.90.12 Files reviewed 135 Size 278.8 KB Scanned

Summary

Togoder Security scanned the npm package @tanstack/react-query@5.90.12 on Oct 4, 2026. An AI review of 135 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
build/codemods/src/utils/index.cjs safe No malicious patterns detected; this is a benign jscodeshift codemod utility for React Query migrations with no network, filesystem, process, or dynamic execution activity.
build/codemods/src/utils/transformers/query-cache-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/utils/transformers/query-client-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/utils/transformers/use-query-like-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v4/key-transformation.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v4/replace-import-specifier.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v4/utils/replacers/key-replacer.cjs safe No malicious patterns detected; the code is a standard jscodeshift codemod for transforming query key expressions without network, filesystem, or execution abuse.
build/codemods/src/v5/is-loading/is-loading.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/keep-previous-data/keep-previous-data.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/keep-previous-data/utils/already-has-placeholder-data-property.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/remove-overloads/remove-overloads.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/remove-overloads/transformers/filter-aware-usage-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/remove-overloads/transformers/query-fn-aware-usage-transformer.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/remove-overloads/utils/index.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/remove-overloads/utils/unknown-usage-error.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/rename-hydrate/rename-hydrate.cjs safe Cleared by Jev triage; no further analysis needed
build/codemods/src/v5/rename-properties/rename-properties.cjs safe Cleared by Jev triage; no further analysis needed
build/legacy/HydrationBoundary.cjs safe This is a standard TanStack Query React HydrationBoundary component transpiled to CommonJS; no malicious patterns, obfuscation, exfiltration, or dynamic code execution are present.
build/legacy/HydrationBoundary.js safe No malicious patterns detected
build/legacy/IsRestoringProvider.cjs safe No malicious patterns detected; this is a standard React context provider shim with no network, filesystem, or process activity.
build/legacy/IsRestoringProvider.js safe No malicious patterns detected
build/legacy/QueryClientProvider.cjs safe This is a standard React Query Client Provider module with no malicious patterns detected.
build/legacy/QueryClientProvider.js safe No malicious patterns detected; the code is a standard React context provider for TanStack Query without any suspicious behavior.
build/legacy/QueryErrorResetBoundary.cjs safe No malicious patterns detected
build/legacy/QueryErrorResetBoundary.js safe No malicious patterns detected; the code is a standard React error boundary context implementation with no exfiltration, obfuscation, or dynamic code execution.
Show 110 more files
FileVerdictWhat the reviewer saw
build/legacy/errorBoundaryUtils.cjs safe No malicious patterns detected; the code is a standard compiled React Query error boundary utility with no data exfiltration, obfuscation, or suspicious behavior.
build/legacy/errorBoundaryUtils.js safe No malicious patterns detected; the code is a legitimate React error boundary utility for TanStack Query.
build/legacy/index.cjs safe This is a standard CommonJS build artifact for TanStack Query React bindings with no malicious patterns detected.
build/legacy/index.js safe No malicious patterns detected; this is a standard re-export module for the TanStack React Query library.
build/legacy/infiniteQueryOptions.cjs safe No malicious patterns detected
build/legacy/infiniteQueryOptions.js safe No malicious patterns detected
build/legacy/mutationOptions.cjs safe No malicious patterns detected; the file contains only standard CommonJS export boilerplate and a trivial identity function.
build/legacy/mutationOptions.js safe The file contains a trivial identity function that returns its input, with no network, filesystem, process, or dynamic execution behavior.
build/legacy/queryOptions.cjs safe No malicious patterns detected
build/legacy/queryOptions.js safe No malicious patterns detected
build/legacy/suspense.cjs safe No malicious patterns detected; this is a standard library build artifact with utility functions for suspense handling.
build/legacy/suspense.js safe No malicious patterns detected; the code is a legitimate React Query suspense utility with no network, filesystem, or dynamic execution activity.
build/legacy/types.cjs safe No malicious patterns detected; the file only contains standard TypeScript/ESBuild CommonJS interop helpers and an empty export map.
build/legacy/types.js safe No malicious patterns detected
build/legacy/useBaseQuery.cjs safe No malicious patterns detected; the file is a standard TanStack Query React hook with only benign runtime behavior and no data exfiltration, credential harvesting, obfuscated payloads, or process/network abuse.
build/legacy/useBaseQuery.js safe No malicious patterns detected; the code is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, or process execution.
build/legacy/useInfiniteQuery.cjs safe This is a benign CommonJS build artifact of a TanStack Query useInfiniteQuery hook with no malicious patterns detected.
build/legacy/useInfiniteQuery.js safe No malicious patterns detected
build/legacy/useIsFetching.cjs safe No malicious patterns detected
build/legacy/useIsFetching.js safe No malicious patterns detected; the code is a legitimate React hook from TanStack Query for tracking fetching state.
build/legacy/useMutation.cjs safe This is a standard TanStack Query useMutation React hook build file with no malicious patterns, data exfiltration, or suspicious behavior detected.
build/legacy/useMutation.js safe No malicious patterns detected
build/legacy/useMutationState.cjs safe No malicious patterns detected
build/legacy/useMutationState.js safe No malicious patterns detected
build/legacy/usePrefetchInfiniteQuery.cjs safe No malicious patterns detected; this is a standard CommonJS build artifact of a TanStack Query hook that only prefetches infinite queries via the local QueryClient.
build/legacy/usePrefetchInfiniteQuery.js safe No malicious patterns detected; the file is a standard React Query prefetch hook with no suspicious behavior.
build/legacy/usePrefetchQuery.cjs safe No malicious patterns detected
build/legacy/usePrefetchQuery.js safe No malicious patterns detected; the code is a standard React Query prefetch hook with no exfiltration, obfuscation, or dynamic execution.
build/legacy/useQueries.cjs safe No malicious patterns detected; this is a standard TanStack Query React hook module.
build/legacy/useQueries.js safe No malicious patterns detected; this is a legitimate React hook implementation from TanStack Query's useQueries module.
build/legacy/useQuery.cjs safe This is a standard TanStack Query React hook build artifact containing only module export boilerplate and a simple delegation to useBaseQuery, with no malicious patterns detected.
build/legacy/useQuery.js safe No malicious patterns detected
build/legacy/useSuspenseInfiniteQuery.cjs safe No malicious patterns detected; this is a standard TanStack Query module that wraps useBaseQuery with no network, filesystem, or process access.
build/legacy/useSuspenseInfiniteQuery.js safe No malicious patterns detected
build/legacy/useSuspenseQueries.cjs safe No malicious patterns detected
build/legacy/useSuspenseQueries.js safe No malicious patterns detected; this is a legitimate TanStack Query React hook for suspense-enabled queries.
build/legacy/useSuspenseQuery.cjs safe No malicious patterns detected; the file is a standard TanStack Query React hook build artifact with no data exfiltration, credential harvesting, obfuscation, or process/network manipulation.
build/legacy/useSuspenseQuery.js safe No malicious patterns detected
build/modern/HydrationBoundary.cjs safe This is a standard TanStack Query React HydrationBoundary component transpiled to CommonJS; no malicious patterns, obfuscation, exfiltration, or dynamic code execution are present.
build/modern/HydrationBoundary.js safe No malicious patterns detected
build/modern/IsRestoringProvider.cjs safe No malicious patterns detected; this is a standard React context provider shim with no network, filesystem, or process activity.
build/modern/IsRestoringProvider.js safe No malicious patterns detected
build/modern/QueryClientProvider.cjs safe This is a standard React Query Client Provider module with no malicious patterns detected.
build/modern/QueryClientProvider.js safe No malicious patterns detected; the code is a standard React context provider for TanStack Query without any suspicious behavior.
build/modern/QueryErrorResetBoundary.cjs safe No malicious patterns detected
build/modern/QueryErrorResetBoundary.js safe No malicious patterns detected; the code is a standard React error boundary context implementation with no exfiltration, obfuscation, or dynamic code execution.
build/modern/errorBoundaryUtils.cjs safe No malicious patterns detected; the code is a standard compiled React Query error boundary utility with no data exfiltration, obfuscation, or suspicious behavior.
build/modern/errorBoundaryUtils.js safe No malicious patterns detected; the code is a legitimate React error boundary utility for TanStack Query.
build/modern/index.cjs safe This is a standard CommonJS build artifact for TanStack Query React bindings with no malicious patterns detected.
build/modern/index.js safe No malicious patterns detected; this is a standard re-export module for the TanStack React Query library.
build/modern/infiniteQueryOptions.cjs safe No malicious patterns detected
build/modern/infiniteQueryOptions.js safe No malicious patterns detected
build/modern/mutationOptions.cjs safe No malicious patterns detected; the file contains only standard CommonJS export boilerplate and a trivial identity function.
build/modern/mutationOptions.js safe The file contains a trivial identity function that returns its input, with no network, filesystem, process, or dynamic execution behavior.
build/modern/queryOptions.cjs safe No malicious patterns detected
build/modern/queryOptions.js safe No malicious patterns detected
build/modern/suspense.cjs safe No malicious patterns detected; the code is a standard CommonJS build artifact for React Query suspense utilities with no network, filesystem, credential, or execution-related concerns.
build/modern/suspense.js safe No malicious patterns detected; the file contains legitimate React suspense utility logic for a query library.
build/modern/types.cjs safe No malicious patterns detected; the file only contains standard TypeScript/ESBuild CommonJS interop helpers and an empty export map.
build/modern/types.js safe No malicious patterns detected
build/modern/useBaseQuery.cjs safe This is a standard TanStack React Query build artifact with no malicious patterns, network calls, credential access, or dynamic code execution.
build/modern/useBaseQuery.js safe No malicious patterns detected in the provided React hook implementation; it contains standard TanStack Query logic with no data exfiltration, credential harvesting, obfuscation, or shell/process execution.
build/modern/useInfiniteQuery.cjs safe This is a benign CommonJS build artifact of a TanStack Query useInfiniteQuery hook with no malicious patterns detected.
build/modern/useInfiniteQuery.js safe No malicious patterns detected
build/modern/useIsFetching.cjs safe No malicious patterns detected
build/modern/useIsFetching.js safe No malicious patterns detected; the code is a legitimate React hook from TanStack Query for tracking fetching state.
build/modern/useMutation.cjs safe This is a standard TanStack Query useMutation React hook build file with no malicious patterns, data exfiltration, or suspicious behavior detected.
build/modern/useMutation.js safe No malicious patterns detected
build/modern/useMutationState.cjs safe No malicious patterns detected
build/modern/useMutationState.js safe No malicious patterns detected
build/modern/usePrefetchInfiniteQuery.cjs safe No malicious patterns detected; this is a standard CommonJS build artifact of a TanStack Query hook that only prefetches infinite queries via the local QueryClient.
build/modern/usePrefetchInfiniteQuery.js safe No malicious patterns detected; the file is a standard React Query prefetch hook with no suspicious behavior.
build/modern/usePrefetchQuery.cjs safe No malicious patterns detected
build/modern/usePrefetchQuery.js safe No malicious patterns detected; the code is a standard React Query prefetch hook with no exfiltration, obfuscation, or dynamic execution.
build/modern/useQueries.cjs safe No malicious patterns detected; the file is a standard compiled React hook from TanStack Query with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/modern/useQueries.js safe No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
build/modern/useQuery.cjs safe This is a standard TanStack Query React hook build artifact containing only module export boilerplate and a simple delegation to useBaseQuery, with no malicious patterns detected.
build/modern/useQuery.js safe No malicious patterns detected
build/modern/useSuspenseInfiniteQuery.cjs safe No malicious patterns detected; this is a standard TanStack Query module that wraps useBaseQuery with no network, filesystem, or process access.
build/modern/useSuspenseInfiniteQuery.js safe No malicious patterns detected
build/modern/useSuspenseQueries.cjs safe No malicious patterns detected
build/modern/useSuspenseQueries.js safe No malicious patterns detected; this is a legitimate TanStack Query React hook for suspense-enabled queries.
build/modern/useSuspenseQuery.cjs safe No malicious patterns detected; the file is a standard TanStack Query React hook build artifact with no data exfiltration, credential harvesting, obfuscation, or process/network manipulation.
build/modern/useSuspenseQuery.js safe No malicious patterns detected
build/query-codemods/eslint.config.js safe Cleared by Jev triage; no further analysis needed
build/query-codemods/root.eslint.config.js safe Cleared by Jev triage; no further analysis needed
build/query-codemods/vite.config.ts safe Cleared by Jev triage; no further analysis needed
src/HydrationBoundary.tsx safe Cleared by Jev triage; no further analysis needed
src/IsRestoringProvider.ts safe Cleared by Jev triage; no further analysis needed
src/QueryClientProvider.tsx safe Cleared by Jev triage; no further analysis needed
src/QueryErrorResetBoundary.tsx safe Cleared by Jev triage; no further analysis needed
src/errorBoundaryUtils.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/infiniteQueryOptions.ts safe Cleared by Jev triage; no further analysis needed
src/mutationOptions.ts safe Cleared by Jev triage; no further analysis needed
src/queryOptions.ts safe Cleared by Jev triage; no further analysis needed
src/suspense.ts safe Cleared by Jev triage; no further analysis needed
src/types.ts safe Cleared by Jev triage; no further analysis needed
src/useBaseQuery.ts safe Cleared by Jev triage; no further analysis needed
src/useInfiniteQuery.ts safe Cleared by Jev triage; no further analysis needed
src/useIsFetching.ts safe Cleared by Jev triage; no further analysis needed
src/useMutation.ts safe Cleared by Jev triage; no further analysis needed
src/useMutationState.ts safe Cleared by Jev triage; no further analysis needed
src/usePrefetchInfiniteQuery.tsx safe Cleared by Jev triage; no further analysis needed
src/usePrefetchQuery.tsx safe No malicious patterns detected; the code is a standard TanStack Query prefetch hook with no network, filesystem, process, or obfuscation concerns.
src/useQueries.ts safe Cleared by Jev triage; no further analysis needed
src/useQuery.ts safe Cleared by Jev triage; no further analysis needed
src/useSuspenseInfiniteQuery.ts safe Cleared by Jev triage; no further analysis needed
src/useSuspenseQueries.ts safe No malicious patterns detected; the code is a standard TanStack Query hook for suspense queries with only type-level complexity and a development-only console error for skipToken misuse.
src/useSuspenseQuery.ts safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of @tanstack/react-query are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.50.15.104.1
VersionsVerdictCountRangeTop findings
5.104.1 No issues 1 5.104.1
5.101.2 โ€“ 5.103.2 Not scanned 2 >=5.101.2 <=5.103.2
5.90.12 No issues 1 5.90.12
5.50.1 Not scanned 1 5.50.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @tanstack/react-query

VersionVerdictFilesScanned
5.104.1 No issues 134 Oct 6, 2026
5.90.12 No issues 135 Oct 4, 2026

Frequently asked questions

Is @tanstack/react-query safe to use?

Our AI source review of @tanstack/react-query@5.90.12 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @tanstack/react-query contain malware?

No malware was identified in @tanstack/react-query@5.90.12 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @tanstack/react-query checked?

Togoder Security downloaded the published npm package and had an AI model read its 135 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @tanstack/react-query together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tanstack/react-query@5.90.12, cost nothing.

Related security reports