Firebase security check

Your Firebase config is public by design. What protects your data is your Security Rules. HatTest checks, from the outside, whether those rules actually hold.

One ordinary visit to the page you enter — what any browser sees. No scan, nothing stored.

What goes wrong

Every Firebase web app ships its config, including the API key, to the browser. That is expected: the key identifies your project, it does not grant access. Access is decided by your Firebase Security Rules.

  • Rules left open. Test-mode rules that were never tightened, or a rule like allow read: if true, let anyone read the data.
  • Realtime Database readable at the root. One open path can expose the whole tree.
  • A Storage bucket that lists its files. Anyone can see, and often download, what is inside.
  • A service-account key served as a file. Unlike the web API key, that key grants real administrative access.

What HatTest checks

The free scan asks as the anonymous public: what can a stranger read or reach? The deep scan signs in as two test accounts you create in your own app and checks whether one user can reach the other’s data. These are the checks that matter most here; the full catalog runs 156.

  • high Firestore collection is world-readable (open security rules)
  • high Firebase Realtime Database is world-readable (open security rules)
  • high Firebase Storage bucket lists objects to anonymous users (open security rules)
  • high Cloud service-account key file publicly served
  • info Google/Firebase API key found
  • info Firebase open registration is enabled
  • low Firebase authorized domains include a wildcard
  • high Authenticated user can read another user's sensitive rows Deep scan
  • medium Authenticated user can write another user's row (writes not owner-scoped — confirm intended) Deep scan Off by default

What’s free, and what it never does

Running a scan is free (up to 5 a day), and so are the severity scoreboard, the informational findings and your site profile. The negative findings, each with its evidence and a plain-English fix, are a $50 unlock per report.

  • It never runs your code. It looks at what your live app already serves and answers.
  • It only scans a site you have verified you own. The no-signup check above is the exception, and it only reads what any browser sees.
  • It does not write to your data. Every check that would write is switched off on this deployment, marked above.
  • It never tells you a site is “secure.” It reports what it found, and names anything it could not check.

Questions

Is my Firebase API key a secret?

No. A Firebase web API key is meant to be in your app's code, and HatTest reports it only as informational. What matters is what your Security Rules allow, which is what the scan tests.

Which Firebase products does it check?

Firestore, the Realtime Database and Cloud Storage, each read the way an anonymous visitor could, plus your sign-up and authorized-domain settings and any service-account key served as a public file.

Does it change anything in my project?

The standard scan only reads. Checks that would write are switched off on this deployment unless the list above shows otherwise.

Run the full scan, free