firebase
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
SecuritySecurityreferences/firestore-database.md
MEDIUMSecurityMEDIUM
references/firestore-database.md
No malicious or obfuscated code is present. The principal risk is an insecure Firestore ruleset: broad `allow write` validation rules are ORed with authorization rules and can permit unauthenticated or unauthorized writes to users and posts. Public user reads expose email and other profile data. Restrict writes to authenticated owners/admins, validate immutable and permitted fields explicitly, protect role and authorId, and avoid public reads of sensitive user data.
Confidence: 98%Severity: 86%
Audit Metadata