Skip to main content

FireFetch

A Firebase audit tool, mostly aimed at mobile apps.

Point it at an APK, an Android package name, or a set of Firebase values you already have. It checks Remote Config, Realtime Database, Firestore, Cloud Storage, Auth, and Hosting and tells you what's exposed.

Install

pipx install firefetch

Use it

# you already have the apk
firefetch apk app-release.apk

# you only know the package name
firefetch apk com.example.app

# no apk; just creds you already have
firefetch manual --project-id foo --api-key AIzaSy... --app-id 1:1234:android:abc

Handy flags: --json out.json for a structured dump, --no-write to skip write probes (on by default; they write a tiny payload at a unique path and delete it). firefetch apk --help for the rest.

What you get

Dev

git clone https://github.com/bitthebyte/firefetch
cd firefetch
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pytest

Metadata

Release files for firefetch 0.2.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for firefetch 0.2.3
File Size Uploaded
firefetch-0.2.3.tar.gz 24.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for firefetch 0.2.3
File Interpreter ABI Platform
firefetch-0.2.3-py3-none-any.whl Python 3 none any Details

Total release size: 50.8 kB

Release files / firefetch-0.2.3.tar.gz

Download URL firefetch-0.2.3.tar.gz
Size 24.5 kB
Tags Source
SHA-256 checksum
How to use checksums
c62d70b64a64f217903543affaf326542952253aa00d7301fd29b58d5b1bfafe
BLAKE2b-256 checksum
How to use checksums
c40ca378194140dc5dcea91291929421520425298fc62c75861e8b80deb2beaf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.12

Release files / firefetch-0.2.3-py3-none-any.whl

Download URL firefetch-0.2.3-py3-none-any.whl
Size 26.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1c01d4764ad3bb2e235a64e2da03f54ef03c70ac5f1ac2b6cd7f16cea53b29b6
BLAKE2b-256 checksum
How to use checksums
51b1de80cf7f6472b9e91db3640d59ab68bbe224313f8d794ae2b970831c7219
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

0.2.3 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page