# @tanstack/react-query@5.90.12 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:18:18.000Z
- Files reviewed: 135
- Findings: no findings
- Report: https://security.togoder.click/npm/@tanstack/react-query@5.90.12
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @tanstack/react-query@5.90.12 on Oct 4, 2026. An AI review of 135 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `build/codemods/src/utils/index.cjs` (safe): No malicious patterns detected; this is a benign jscodeshift codemod utility for React Query migrations with no network, filesystem, process, or dynamic execution activity.
- `build/codemods/src/utils/transformers/query-cache-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/utils/transformers/query-client-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/utils/transformers/use-query-like-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v4/key-transformation.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v4/replace-import-specifier.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v4/utils/replacers/key-replacer.cjs` (safe): No malicious patterns detected; the code is a standard jscodeshift codemod for transforming query key expressions without network, filesystem, or execution abuse.
- `build/codemods/src/v5/is-loading/is-loading.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/keep-previous-data/keep-previous-data.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/keep-previous-data/utils/already-has-placeholder-data-property.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/remove-overloads/remove-overloads.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/remove-overloads/transformers/filter-aware-usage-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/remove-overloads/transformers/query-fn-aware-usage-transformer.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/remove-overloads/utils/index.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/remove-overloads/utils/unknown-usage-error.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/rename-hydrate/rename-hydrate.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/codemods/src/v5/rename-properties/rename-properties.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `build/legacy/HydrationBoundary.cjs` (safe): This is a standard TanStack Query React HydrationBoundary component transpiled to CommonJS; no malicious patterns, obfuscation, exfiltration, or dynamic code execution are present.
- `build/legacy/HydrationBoundary.js` (safe): No malicious patterns detected
- `build/legacy/IsRestoringProvider.cjs` (safe): No malicious patterns detected; this is a standard React context provider shim with no network, filesystem, or process activity.
- `build/legacy/IsRestoringProvider.js` (safe): No malicious patterns detected
- `build/legacy/QueryClientProvider.cjs` (safe): This is a standard React Query Client Provider module with no malicious patterns detected.
- `build/legacy/QueryClientProvider.js` (safe): No malicious patterns detected; the code is a standard React context provider for TanStack Query without any suspicious behavior.
- `build/legacy/QueryErrorResetBoundary.cjs` (safe): No malicious patterns detected
- `build/legacy/QueryErrorResetBoundary.js` (safe): No malicious patterns detected; the code is a standard React error boundary context implementation with no exfiltration, obfuscation, or dynamic code execution.
- `build/legacy/errorBoundaryUtils.cjs` (safe): No malicious patterns detected; the code is a standard compiled React Query error boundary utility with no data exfiltration, obfuscation, or suspicious behavior.
- `build/legacy/errorBoundaryUtils.js` (safe): No malicious patterns detected; the code is a legitimate React error boundary utility for TanStack Query.
- `build/legacy/index.cjs` (safe): This is a standard CommonJS build artifact for TanStack Query React bindings with no malicious patterns detected.
- `build/legacy/index.js` (safe): No malicious patterns detected; this is a standard re-export module for the TanStack React Query library.
- `build/legacy/infiniteQueryOptions.cjs` (safe): No malicious patterns detected
- `build/legacy/infiniteQueryOptions.js` (safe): No malicious patterns detected
- `build/legacy/mutationOptions.cjs` (safe): No malicious patterns detected; the file contains only standard CommonJS export boilerplate and a trivial identity function.
- `build/legacy/mutationOptions.js` (safe): The file contains a trivial identity function that returns its input, with no network, filesystem, process, or dynamic execution behavior.
- `build/legacy/queryOptions.cjs` (safe): No malicious patterns detected
- `build/legacy/queryOptions.js` (safe): No malicious patterns detected
- `build/legacy/suspense.cjs` (safe): No malicious patterns detected; this is a standard library build artifact with utility functions for suspense handling.
- `build/legacy/suspense.js` (safe): No malicious patterns detected; the code is a legitimate React Query suspense utility with no network, filesystem, or dynamic execution activity.
- `build/legacy/types.cjs` (safe): No malicious patterns detected; the file only contains standard TypeScript/ESBuild CommonJS interop helpers and an empty export map.
- `build/legacy/types.js` (safe): No malicious patterns detected
- `build/legacy/useBaseQuery.cjs` (safe): No malicious patterns detected; the file is a standard TanStack Query React hook with only benign runtime behavior and no data exfiltration, credential harvesting, obfuscated payloads, or process/network abuse.
- `build/legacy/useBaseQuery.js` (safe): No malicious patterns detected; the code is a legitimate TanStack Query React hook with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `build/legacy/useInfiniteQuery.cjs` (safe): This is a benign CommonJS build artifact of a TanStack Query useInfiniteQuery hook with no malicious patterns detected.
- `build/legacy/useInfiniteQuery.js` (safe): No malicious patterns detected
- `build/legacy/useIsFetching.cjs` (safe): No malicious patterns detected
- `build/legacy/useIsFetching.js` (safe): No malicious patterns detected; the code is a legitimate React hook from TanStack Query for tracking fetching state.
- `build/legacy/useMutation.cjs` (safe): This is a standard TanStack Query useMutation React hook build file with no malicious patterns, data exfiltration, or suspicious behavior detected.
- `build/legacy/useMutation.js` (safe): No malicious patterns detected
- `build/legacy/useMutationState.cjs` (safe): No malicious patterns detected
- `build/legacy/useMutationState.js` (safe): No malicious patterns detected
- `build/legacy/usePrefetchInfiniteQuery.cjs` (safe): No malicious patterns detected; this is a standard CommonJS build artifact of a TanStack Query hook that only prefetches infinite queries via the local QueryClient.
- `build/legacy/usePrefetchInfiniteQuery.js` (safe): No malicious patterns detected; the file is a standard React Query prefetch hook with no suspicious behavior.
- `build/legacy/usePrefetchQuery.cjs` (safe): No malicious patterns detected
- `build/legacy/usePrefetchQuery.js` (safe): No malicious patterns detected; the code is a standard React Query prefetch hook with no exfiltration, obfuscation, or dynamic execution.
- `build/legacy/useQueries.cjs` (safe): No malicious patterns detected; this is a standard TanStack Query React hook module.
- `build/legacy/useQueries.js` (safe): No malicious patterns detected; this is a legitimate React hook implementation from TanStack Query's useQueries module.
- `build/legacy/useQuery.cjs` (safe): This is a standard TanStack Query React hook build artifact containing only module export boilerplate and a simple delegation to useBaseQuery, with no malicious patterns detected.
- `build/legacy/useQuery.js` (safe): No malicious patterns detected
- `build/legacy/useSuspenseInfiniteQuery.cjs` (safe): No malicious patterns detected; this is a standard TanStack Query module that wraps useBaseQuery with no network, filesystem, or process access.
- `build/legacy/useSuspenseInfiniteQuery.js` (safe): No malicious patterns detected
- `build/legacy/useSuspenseQueries.cjs` (safe): No malicious patterns detected
- `build/legacy/useSuspenseQueries.js` (safe): No malicious patterns detected; this is a legitimate TanStack Query React hook for suspense-enabled queries.
- `build/legacy/useSuspenseQuery.cjs` (safe): No malicious patterns detected; the file is a standard TanStack Query React hook build artifact with no data exfiltration, credential harvesting, obfuscation, or process/network manipulation.
- `build/legacy/useSuspenseQuery.js` (safe): No malicious patterns detected
- `build/modern/HydrationBoundary.cjs` (safe): This is a standard TanStack Query React HydrationBoundary component transpiled to CommonJS; no malicious patterns, obfuscation, exfiltration, or dynamic code execution are present.
- `build/modern/HydrationBoundary.js` (safe): No malicious patterns detected
- `build/modern/IsRestoringProvider.cjs` (safe): No malicious patterns detected; this is a standard React context provider shim with no network, filesystem, or process activity.
- `build/modern/IsRestoringProvider.js` (safe): No malicious patterns detected
- `build/modern/QueryClientProvider.cjs` (safe): This is a standard React Query Client Provider module with no malicious patterns detected.
- `build/modern/QueryClientProvider.js` (safe): No malicious patterns detected; the code is a standard React context provider for TanStack Query without any suspicious behavior.
- `build/modern/QueryErrorResetBoundary.cjs` (safe): No malicious patterns detected
- `build/modern/QueryErrorResetBoundary.js` (safe): No malicious patterns detected; the code is a standard React error boundary context implementation with no exfiltration, obfuscation, or dynamic code execution.
- `build/modern/errorBoundaryUtils.cjs` (safe): No malicious patterns detected; the code is a standard compiled React Query error boundary utility with no data exfiltration, obfuscation, or suspicious behavior.
- `build/modern/errorBoundaryUtils.js` (safe): No malicious patterns detected; the code is a legitimate React error boundary utility for TanStack Query.
- `build/modern/index.cjs` (safe): This is a standard CommonJS build artifact for TanStack Query React bindings with no malicious patterns detected.
- `build/modern/index.js` (safe): No malicious patterns detected; this is a standard re-export module for the TanStack React Query library.
- `build/modern/infiniteQueryOptions.cjs` (safe): No malicious patterns detected
- `build/modern/infiniteQueryOptions.js` (safe): No malicious patterns detected
- `build/modern/mutationOptions.cjs` (safe): No malicious patterns detected; the file contains only standard CommonJS export boilerplate and a trivial identity function.
- `build/modern/mutationOptions.js` (safe): The file contains a trivial identity function that returns its input, with no network, filesystem, process, or dynamic execution behavior.
- `build/modern/queryOptions.cjs` (safe): No malicious patterns detected
- `build/modern/queryOptions.js` (safe): No malicious patterns detected
- `build/modern/suspense.cjs` (safe): No malicious patterns detected; the code is a standard CommonJS build artifact for React Query suspense utilities with no network, filesystem, credential, or execution-related concerns.
- `build/modern/suspense.js` (safe): No malicious patterns detected; the file contains legitimate React suspense utility logic for a query library.
- `build/modern/types.cjs` (safe): No malicious patterns detected; the file only contains standard TypeScript/ESBuild CommonJS interop helpers and an empty export map.
- `build/modern/types.js` (safe): No malicious patterns detected
- `build/modern/useBaseQuery.cjs` (safe): This is a standard TanStack React Query build artifact with no malicious patterns, network calls, credential access, or dynamic code execution.
- `build/modern/useBaseQuery.js` (safe): No malicious patterns detected in the provided React hook implementation; it contains standard TanStack Query logic with no data exfiltration, credential harvesting, obfuscation, or shell/process execution.
- `build/modern/useInfiniteQuery.cjs` (safe): This is a benign CommonJS build artifact of a TanStack Query useInfiniteQuery hook with no malicious patterns detected.
- `build/modern/useInfiniteQuery.js` (safe): No malicious patterns detected
- `build/modern/useIsFetching.cjs` (safe): No malicious patterns detected
- `build/modern/useIsFetching.js` (safe): No malicious patterns detected; the code is a legitimate React hook from TanStack Query for tracking fetching state.
- `build/modern/useMutation.cjs` (safe): This is a standard TanStack Query useMutation React hook build file with no malicious patterns, data exfiltration, or suspicious behavior detected.
- `build/modern/useMutation.js` (safe): No malicious patterns detected
- `build/modern/useMutationState.cjs` (safe): No malicious patterns detected
- `build/modern/useMutationState.js` (safe): No malicious patterns detected
- `build/modern/usePrefetchInfiniteQuery.cjs` (safe): No malicious patterns detected; this is a standard CommonJS build artifact of a TanStack Query hook that only prefetches infinite queries via the local QueryClient.
- `build/modern/usePrefetchInfiniteQuery.js` (safe): No malicious patterns detected; the file is a standard React Query prefetch hook with no suspicious behavior.
- `build/modern/usePrefetchQuery.cjs` (safe): No malicious patterns detected
- `build/modern/usePrefetchQuery.js` (safe): No malicious patterns detected; the code is a standard React Query prefetch hook with no exfiltration, obfuscation, or dynamic execution.
- `build/modern/useQueries.cjs` (safe): No malicious patterns detected; the file is a standard compiled React hook from TanStack Query with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/modern/useQueries.js` (safe): No malicious patterns detected; the file is a legitimate React hook implementation from TanStack Query with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `build/modern/useQuery.cjs` (safe): This is a standard TanStack Query React hook build artifact containing only module export boilerplate and a simple delegation to useBaseQuery, with no malicious patterns detected.
- `build/modern/useQuery.js` (safe): No malicious patterns detected
- `build/modern/useSuspenseInfiniteQuery.cjs` (safe): No malicious patterns detected; this is a standard TanStack Query module that wraps useBaseQuery with no network, filesystem, or process access.
- `build/modern/useSuspenseInfiniteQuery.js` (safe): No malicious patterns detected
- `build/modern/useSuspenseQueries.cjs` (safe): No malicious patterns detected
- `build/modern/useSuspenseQueries.js` (safe): No malicious patterns detected; this is a legitimate TanStack Query React hook for suspense-enabled queries.
- `build/modern/useSuspenseQuery.cjs` (safe): No malicious patterns detected; the file is a standard TanStack Query React hook build artifact with no data exfiltration, credential harvesting, obfuscation, or process/network manipulation.
- `build/modern/useSuspenseQuery.js` (safe): No malicious patterns detected
- `build/query-codemods/eslint.config.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/query-codemods/root.eslint.config.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/query-codemods/vite.config.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/HydrationBoundary.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/IsRestoringProvider.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/QueryClientProvider.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/QueryErrorResetBoundary.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/errorBoundaryUtils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/infiniteQueryOptions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mutationOptions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/queryOptions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/suspense.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/types.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useBaseQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useInfiniteQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useIsFetching.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useMutation.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useMutationState.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/usePrefetchInfiniteQuery.tsx` (safe): Cleared by Jev triage; no further analysis needed
- `src/usePrefetchQuery.tsx` (safe): No malicious patterns detected; the code is a standard TanStack Query prefetch hook with no network, filesystem, process, or obfuscation concerns.
- `src/useQueries.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useSuspenseInfiniteQuery.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/useSuspenseQueries.ts` (safe): No malicious patterns detected; the code is a standard TanStack Query hook for suspense queries with only type-level complexity and a development-only console error for skipToken misuse.
- `src/useSuspenseQuery.ts` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of @tanstack/react-query are flagged high or critical. The latest scanned version, 5.104.1, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.104.1 (`5.104.1`): clean
- 5.101.2 – 5.103.2 (`>=5.101.2 <=5.103.2`): not scanned
- 5.90.12 (`5.90.12`): clean
- 5.50.1 (`5.50.1`): not scanned

## Scanned versions

- [5.104.1](https://security.togoder.click/npm/@tanstack/react-query@5.104.1): safe, 2026-10-06T14:12:47.000Z
- [5.90.12](https://security.togoder.click/npm/@tanstack/react-query@5.90.12): safe, 2026-10-04T16:18:18.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
