Firepwn is a tool made for testing the Security Rules of a firebase application.
-
Updated
Mar 10, 2026 - TypeScript
Firepwn is a tool made for testing the Security Rules of a firebase application.
A comprehensive Firebase security auditing tool with an interactive console.
Automated Firebase recon and security scanner. Extracts from APKs or IPAs and checks for unauthorized read and write access on Firestore, Realtime Database, Storage buckets, Remote Config, Cloud Functions, and hardcoded service accounts.
Firebase client tools for security assessment or penetration testing.
A practical Firebase pentest checklist covering Auth, Realtime database, Firestore, Storage, Remote Config, Functions, and IAM. Includes OpenFirebase commands and clear finding criteria per service
Security tool to easily exploit Firebase and show impact, if you manage to find a leaked service account and its private key
Add a description, image, and links to the firebase-pentest topic page so that developers can more easily learn about it.
To associate your repository with the firebase-pentest topic, visit your repo's landing page and select "manage topics."