@firebase/app Types
87%
Total Score
healthy
Healthy: sustained Firebase maintenance and strong repository activity outweigh minor workflow and package-identification caveats.
The repository name does not match the package and its README does not mention @firebase/app-types, so package ownership is less transparent. The Firebase monorepo backing and the package's explicit internal-use description partly compensate for this mismatch.
The repository uses established build tooling including TypeScript, Rollup, Webpack, Babel, and Nx. No security scanning tools were detected, leaving a minor process gap.
Version 0.9.6 is a stable release rather than a prerelease, although the recent prerelease share is high at 85%, which adds a modest maturity caveat.
All 21 workflows were analyzed with no untrusted checkouts, script injection, top-level write permissions, or unpinned actions. A high-confidence ad hoc package installation remains a minor workflow hygiene concern; the low-confidence cache finding is not independently weighty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@firebase/logger Version 0.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.