@firebase/performance Types
88%
Total Score
healthy
Healthy: active organization-backed project with frequent releases and current repository activity.
The repository name does not match the package and its README does not mention it, which is a transparency caution; the organization-owned Firebase monorepo context partly explains the mismatch.
Version 0.2.5 is not a prerelease, but 90% of recent releases are prereleases, which makes the release stream less predictable.
All 21 workflows were analyzed with no untrusted checkout or script-injection paths, all 106 action references were pinned, and permissions were mostly read-only. The audit still found a high-confidence low-severity ad hoc package install and a low-confidence cache-poisoning pattern, warranting limited caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.