Healthy and suitable to depend on. It has a long release history, frequent recent releases, active maintenance, strong repository practices, and an organization-backed project; the main caveat is that most recent commits come from one contributor and no security policy is published.
91%
Total Score
88
50
100
88
The package has 25 runtime dependencies, including several framework and authentication components; this is a substantial dependency surface, but it is consistent with a full Firebase Admin SDK.
One contributor made 88% of the 25 recent commits, which creates concentration risk; the other three contributors remain active, and organization ownership provides some capacity to hand off maintenance.
No repository security policy is published, leaving vulnerability-reporting guidance less transparent than it could be; the repository's security scanning and workflow controls partly compensate.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10038 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. kreait/firebase-php is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 7.24.0. | 0.0.1 - 7.24.0 | Low |
CVE-2018-1000025 kreait/firebase-php is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 3.2.0 - 3.8.1. | 3.2.0 - 3.8.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
beste/json Version ^1.5.1 | — | — |
beste/clock Version ^3.0 || ^4.0 | — | — |
google/auth Version ^1.45 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.