Vigavo for Firebase

Firebase rules, tested.We stay awake.

Open Firestore collections, Realtime Database and Storage are among the most common leaks. We test them with your public config.

Free. No signup. Read-only checks from the outside.

What we check on Firebase

Your Firebase config is public by design. Your security rules decide what it can reach, and that is what we test.

  1. Firestore

    Collections readable without signing in.

  2. Realtime Database

    A database root that answers anyone.

  3. Storage

    Buckets that list or serve files publicly.

Everything a small team forgets to check

Findings ranked by what an attacker would try first, with the fix right next to each one.

Scan like an attacker, safely

Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.

Watch for changes

Scheduled scans compare against the last result, so you hear about a new leak once, not every day.

Backups that restore

Encrypted database snapshots, verified by an actual restore and row counts.

Fix prompts

Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.

Alerts without noise

Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.

Questions

Is the Firebase API key a secret?

No, it identifies the project. The rules protect the data, so we test the rules.

Do you write to my database?

No. Read probes only.

Do you back up Firestore?

Not yet. Scanning and monitoring work today.

Is the scan safe for my site?

Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.

What do you store?

The scan result. Free scans are deleted after 30 days.

Feedback
Type