Skip to main content
UNPWNED
Firebase Security Guide
Q&AFirebase

How do I secure Firestore properly?

Firestore security requires writing granular Security Rules that validate authentication, authorization, and data structure for every collection and document. Rules should check request.auth and enforce ownership and data constraints. Avoid broad wildcard allow rules. UNPWNED tests bounded anonymous read and access patterns and reports confirmed exposure. It does not parse or certify every Firestore rule.

Check your Firebase app now

Run free security scan

Last reviewed: 2026-04-07. Based on publicly available security research and UNPWNED scan telemetry.