shouldiuse.io

Categories

VERDICT

Should I use TanStack?

The open-source application stack for the web. - tanstack.com

Depends. React teams should adopt the free core libraries — Query, Table, Router — they are proven and cost nothing. Think twice before betting production on TanStack Start, and don't ship it without npm supply-chain protections after the May 2026 attack.

Confidence

Medium. Based on 40+ public sources; many snippets truncated, so quote depth is limited.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
TanStack ShipNot disclosed

Best for

  • React/TypeScript product teams
  • Data-heavy apps needing caching, tables, virtualization
  • Teams leaving for a lighter full-stack setup
  • OSS-first engineering orgs

Not for

  • Non-technical buyers — this is code you assemble, not a product you purchase
  • Teams wanting one vendor with SLAs and support contracts
  • Anyone unwilling to manage npm supply-chain risk
  • Beginners needing a batteries-included framework

Gotchas - check before you buy

high

Pin exact versions and verify package integrity; compromised packages reached npm in May 2026.

medium

No support SLAs — you depend on GitHub issues and community goodwill.

medium

TanStack Start is young; migrating off means rethinking the server/client split.

medium

'TanStack Ship' pricing not disclosed in sources reviewed; zero reviews validate its value.

Pros and cons

Pros

  • Core libraries (Query, Table, Router) are free and widely adopted in React
  • TanStack Start is a lighter full-stack alternative pulling developers from
  • Independently maintained full-time since ~2023
  • Transparent incident response: postmortem and hardening published within days
  • Positioned as a modern alternative to heavyweight frameworks

Cons

  • 42+ npm packages served malware exfiltrating cloud credentials in May 2026
  • CVE-2026-45321: auth bypass in TanStack arktype-adapter
  • Some libraries criticized as overcomplicated
  • Commercial TanStack Ship has zero G2 reviews
  • Sponsor-funded sustainability; community debates whether big firms should pay

Sources & method

Analyzed 9/29/2026 - 12 sources - Compromised in the May 2026 'Mini Shai-Hulud' npm supply-chain attack; postmortem and hardening follow-up published.

official x2review x3security x5news x2
  • Malware in 42 @tanstack/* npm packages, Malicious publishes exfiltrated cloud credentials; part of a worm hitting 160+ npm packages.
  • CVE-2026-45321, Auth bypass in the TanStack arktype-adapter.
  • Grafana Labs GitHub environment breach, Linked to the TanStack npm supply-chain ransomware incident.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free, open source, sponsor-funded
  • Ease of use: 3/5. Powerful but criticized as overcomplicated
  • Feature depth: 4/5. Broad headless ecosystem; few batteries included
  • Support quality: 3/5. Full-time maintainer; community support, no SLA
  • Security posture: 2/5. 2026 npm supply-chain compromise; hardening since
  • $0 Pricing Open-source libraries, sponsor-funded
  • 0 G2 reviews (TanStack Ship) Commercial product, unreviewed
  • 42–84 pkgs May 2026 incident Malicious npm publishes, credential theft
  • ~2023 Full-time OSS since Maintainer Tanner Linsley

Pricing

Open source

$0

  • All core libraries free
  • Community support via GitHub

TanStack Ship

Not disclosed

  • Commercial offering
  • No public pricing in sources reviewed

Security

Compromised in the May 2026 'Mini Shai-Hulud' npm supply-chain attack; postmortem and hardening follow-up published.

  • Malware in 42 @tanstack/* npm packagesMalicious publishes exfiltrated cloud credentials; part of a worm hitting 160+ npm packages.²
  • CVE-2026-45321Auth bypass in the TanStack arktype-adapter.⁵
  • Grafana Labs GitHub environment breachLinked to the TanStack npm supply-chain ransomware incident.

What users say

Developers praise the libraries as powerful and modern but debate complexity, maturity versus Next.js, and post-incident trust.

“TanStack Start isn't bad”
LinkedIn

Alternatives

Compare TanStack with each alternative.

  • Next.js

    Batteries-included React framework; safer default for production apps.

  • React Router

    Simpler routing choice; TanStack Router's main rival.

  • SWR

    Lighter data-fetching library for simple React apps.

    TanStack vs SWR

Companies that use it

Companies that could

  • Vercel Uses instead
Full analysis

Based on 40+ public sources; many snippets truncated, so quote depth is limited.

Free, powerful React OSS libraries. Just survived a May 2026 npm supply-chain attack — pin versions; pilot Start before committing.

Methodology

Based on 40+ public sources; many snippets truncated, so quote depth is limited.

Sources

  1. official
  2. security
  3. security
  4. security
  5. security
  6. news
  7. security
  8. review
  9. official
  10. review
  11. review
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.