The Firebase AI SDK
86%
Total Score
healthy
Active organization-backed project with strong release activity; workflow hygiene and package-to-repository linkage need attention.
No build attestation or trusted-publisher identity is present, leaving publication provenance less transparent than it could be. This is moderated by the active organization-backed project and strong release history.
Three of four publishing accounts use the Google domain, consistent with the organization-backed repository. feiyang.chen (gmail.com) is an outside consumer account, so account hygiene is a minor caution rather than evidence of weak maintenance capacity.
The repository name does not match @firebase/ai and its README does not mention the package. Although a monorepo name mismatch is normal, the absence of a package mention leaves a small linkage concern.
The repository uses established build tooling including Nx, TypeScript, Rollup, Webpack, and Babel. No security-scanning tooling was detected, which is a modest transparency gap for a widely used SDK.
All 21 workflows were analyzed, all 106 action references are pinned, permissions are read-only or job-scoped, and no untrusted checkout or script injection was found. The audit still found high-confidence low-severity adhoc package installation and a low-confidence cache-poisoning pattern, so workflow hygiene is a minor caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.1.0 | — | — |
@firebase/util Version 1.15.3 | — | — |
@firebase/logger Version 0.5.2 | — | — |
@firebase/component Version 0.7.5 | — | — |
@firebase/app-check-interop-types Version 0.3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.