Firebase Deploy security check — check your deploy config free
Audits firebase.json before you run firebase deploy: ignore lists that let .env, source maps and admin keys reach the public bundle, catch-all public roots, and missing response headers. Runs entirely in your browser — nothing is uploaded.
Free here: Audit the firebase.json you have open and name every file your next firebase deploy would publish that should never be public.. In the editor: Audit every firebase.json in a monorepo in one run and export the findings as a Markdown or JSON report you can commit, attach to a release, or hand to a client. — that part asks for a licence key.
Same engine as the VS Code extension, byte for byte.