Firebase admin SDK for Node.js
96%
Total Score
healthy
Healthy and actively maintained, with regular releases, broad contributors, and only minor workflow and provenance gaps.
No build attestation or trusted-publisher provenance is present, leaving the registry artifact's build path less independently verifiable. The mature repository and release history partly compensate, but do not remove this transparency gap.
The package has a prepare install-time script. This is a review point because it runs during installation, but the supplied signals do not show that it is unsafe or unusually broad.
All three workflows were analyzed, use read-only permissions, and pin all 13 action references, with no untrusted checkouts or script injection. Two high-confidence low-severity adhoc-package findings are minor hygiene concerns because workflows install packages outside a lockfile.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jwks-rsa Version ^4.0.1 | — | — |
jsonwebtoken Version ^9.0.0 | — | — |
@fastify/busboy Version ^3.0.0 | — | — |
fast-deep-equal Version ^3.1.1 | — | — |
google-auth-library Version ^11.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.