Probe your Firebase Realtime Database and client config from outside, with nothing to connect.
Overview
Firebase projects are frequently deployed with development-mode security rules that allow unrestricted read access. Our scan reads the Firebase configuration your site ships to the browser, then probes the Realtime Database it points at to see whether the rules let the whole internet read it — the same thing an attacker does, from the same starting point.
What this scanner does
Finds the Firebase config in your page and JavaScript bundles, requests the Realtime Database root without a token to test whether it answers, and flags Firebase credentials that should never have shipped to the browser — service-account private keys and Admin SDK material in particular.
Why it matters
Firebase projects deployed with test-mode rules (`allow read, write: if true`) are completely open to the public internet. Attackers routinely scan for these misconfigured databases and have stolen millions of user records from production Firebase projects with no authentication required.
Common findings
OWASP Top 10 coverage
Get a full report with AI-ready fix prompts in 30 seconds. No setup required.
Related checks
Vulnerability Detection
Detect exposed API keys, tokens, and secrets in your frontend code and responses.
Vulnerability Detection
Test your login, signup, and password reset flows for common security weaknesses.
Configuration Audit
Audit your Supabase project for RLS misconfigurations, exposed APIs, and insecure auth settings.
Configuration Audit
Check if your site has the right HTTP security headers to prevent common attacks.
Configuration Audit
Verify your SSL/TLS configuration, certificate validity, and encryption strength.
Configuration Audit
Audit cookie flags, session management, and token security for your application.