88%
Total Score
100
100
85
88
50
No build attestation or trusted-publisher evidence is present, leaving publication provenance less transparent than it could be. This is a modest concern rather than evidence of an unhealthy project.
The repository name does not match the package and its README does not mention it, so package ownership is less explicit. Because the repository is the Firebase monorepo, the mismatch is consistent with a sub-package, but the missing README mention remains a minor transparency gap.
The repository uses established build tools including TypeScript, Rollup, Webpack, Babel, and Nx. No security-scanning tools were detected, which is a minor tooling gap, but the repository does provide a security policy.
Version 0.5.0 is not at a stable major version, and 80% of recent releases are prereleases, so API maturity is less certain despite the strong release cadence.
All 21 workflows were analyzed, all 106 action references are pinned, and no untrusted checkout or script-injection paths were found. The audit also reported a low-confidence cache-poisoning finding and a high-confidence low-severity adhoc package installation, which are limited hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.1.0 | — | — |
@firebase/util Version 1.15.3 | — | — |
@firebase/component Version 0.7.5 | — | — |
@firebase/functions Version 0.14.0 | — | — |
@firebase/functions-types Version 0.6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.