This release appears safe to depend on from a supply-chain health perspective: it has a long release history with 110 releases in the last 12 months, an actively maintained and non-archived organization-owned repository, substantial recent commit and pull-request activity, multiple active contributors, tests, type declarations, and a declared Apache-2.0 license. The main reservations are the high recent prerelease share, absent build provenance attestation, no detected repository security-scanning tools, and the repository/package identity check not finding the package name in the repository README; however, the repository is the Firebase organization’s large monorepo and contains extensive package and release infrastructure, which partially mitigates that last concern.
88%
Total Score
100
100
85
100
50
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.1.0 | — | — |
@firebase/util Version 1.15.3 | — | — |
@firebase/component Version 0.7.5 | — | — |
@firebase/messaging Version 0.13.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.