Scan like an attacker, safely
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Vigavo for Firebase
Open Firestore collections, Realtime Database and Storage are among the most common leaks. We test them with your public config.
Free. No signup. Read-only checks from the outside.
Your Firebase config is public by design. Your security rules decide what it can reach, and that is what we test.
Collections readable without signing in.
A database root that answers anyone.
Buckets that list or serve files publicly.
Findings ranked by what an attacker would try first, with the fix right next to each one.
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Scheduled scans compare against the last result, so you hear about a new leak once, not every day.
Encrypted database snapshots, verified by an actual restore and row counts.
Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.
Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.
No, it identifies the project. The rules protect the data, so we test the rules.
No. Read probes only.
Not yet. Scanning and monitoring work today.
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
The scan result. Free scans are deleted after 30 days.