World’s largest virtual agentic engineering & quality conference
This free tool allows you to scan a public https URL for leaked keys, weak headers, and missing RLS.
Localhost and private IPs are refused.
Extra probes only. Never writes or logs in.
Scan URL
Sample
Reset
Enter a public https URL and click Scan URL.
A vibe-coded app scanner is a free online check that fetches a public https URL and looks for the gaps AI coding tools tend to ship. You paste the live address. The engine reads headers, HTML, and same-origin JavaScript, then returns a score, a platform fingerprint, and findings with evidence and an AI-ready fix.
Apps built in Lovable, Bolt, Cursor, v0, or Replit often fail in the deployed bundle, not in the chat transcript. A missing RLS policy lives in Supabase. A Stripe live secret shows up only after the host inlines env vars. This scanner starts where an outsider starts, the public URL, and it will not invent a finding it cannot prove.
A demo that logs in and shows rows can still leak those rows to anyone who opens DevTools. Scan the live host before you share it, because the failures below do not break the happy path.
The scan runs against one public URL. You do not install an agent or connect GitHub. Follow these steps:
The scanner is built for deployed AI apps, not for a source zip. Here are the features of the tool:
Use this when you have a public preview or production URL and you want a first pass before users arrive. Pair it with sibling tools when you need a narrower check.
TestMu AI maintains this scanner as part of its free online tools. Processing stays on the scan path you start. Page bodies and extracted secrets are not kept after the report is built.
A vibe-coded app scanner is a read-only check of a live https URL built with AI coding tools. You paste the public address. The scanner fetches the page, headers, and same-origin scripts, then reports a score, platform fingerprint, and findings with an AI-ready fix.
No. The scanner never asks for a repo, zip, or source upload. It fetches the same public https URL a visitor would open, plus a short leftover-file list. If a fact cannot be proven from that outside view, the check is skipped instead of guessed.
The default pass looks at security headers, cookie flags, TLS age, leftover files, secrets in HTML and JS, mixed content, SRI, open redirects already in the HTML, and anonymous Supabase or Firebase reads when those clients appear in the bundle.
Turn deep scan on only when you own the URL or have written permission to test it. That mode adds cheap canaries for reflected XSS, SQL error text, path traversal, leftover admin routes, and URL-accepting parameters. It still never writes to the target.
A skip means the scanner could not prove the issue from the outside, or you did not consent to that probe. Skips do not lower the score. Only findings that came back with evidence count against the 0 to 100 score.
No. The allowlist refuses localhost, RFC1918, link-local, metadata IPs, and non-http(s) schemes. That block is there so the tool cannot be pointed at internal hosts. Enter a public https URL that you are allowed to test.
Copy the finding, rotate the key in the provider console, then remove it from the client bundle. A rescan is not enough if the old key still works. Publishable keys stay informational unless they sit next to a dangerous follow-on.
It does not run IDOR or BOLA with two accounts, stored XSS, webhook HMAC tests, payment or business-logic abuse, or compliance attestations. Those need a human audit. The report states that so a green skip is not read as a pass.
Did you find this page helpful?
TestMu AI forEnterprise
Get access to solutions built on Enterprise
grade security, privacy, & compliance