vibecodeaudit
built by @Ujjvalbhatti007 →
free · no signup · 20 seconds

Your AI-built app works.
Is it safe to take money on?

Lovable, Bolt, Replit, v0 and Cursor get you to a working product in a weekend. They optimise for “it renders”, not “it holds”. Paste your URL and find out what a stranger can already see.

Reads only your public page and the scripts it already loads — the same requests any visitor makes. Nothing is stored.

What gets checked

  1. Secret keys shipped to the browser — Stripe, OpenAI, Anthropic, AWS, Google, GitHub, Razorpay, and Supabase service_role tokens hiding in your bundle.
  2. Public source maps that let anyone rebuild your original code.
  3. Missing security headers — CSP, framing protection, HSTS, nosniff, referrer policy.
  4. Cookies without HttpOnly or Secure flags.
  5. Direct Supabase or Firebase access from the browser, which is only safe if your database rules are switched on.
  6. Which tool built it — Lovable, Bolt, Replit, v0, Base44, Framer, Bubble.