Firebase security rules
Firebase apps send their config (API key, project id) to every visitor; the security rules decide what that config can read. Vigavo asks Firebase what an anonymous visitor can do:
- firebase_rules_open (critical): a Firestore collection or the Realtime Database can be read without signing in. Vigavo tries the collection names it finds in your code plus common ones (users, orders, messages, …).
- firebase_storage_open: files in Cloud Storage can be listed by anyone.
Only collection names, field names and counts are recorded, never the values.
Fixing
Replace open rules (allow read: if true; or test-mode rules) with rules that require request.auth and match the owner of each document. The fix prompt contains a starting point. Deploy the rules, then verify the fix.
Backups of Firebase data are not available yet; see Supported platforms.
Last reviewed Oct 7, 2026, 12:00:00 AM