Qualmly
AI security and QA reviewer for vibe-coded apps — checks for leaked keys, missing Supabase RLS and exposed routes in 30 seconds.
Visit Qualmly
qualmly.devAbout Qualmly
Qualmly is an AI reviewer aimed specifically at applications shipped out of Lovable, Bolt, v0, Cursor, GitHub Copilot, Claude Code, Windsurf, Replit and Webflow — the class of app where nobody on the team is necessarily an engineer and the failure modes are consistent enough to check for by name. You paste an app URL, or the raw HTML when the app sits behind a login or blocks crawlers, pick the app type, and it returns findings across eight test categories in plain English in about thirty seconds. The Vibe-Coded App preset targets the specific patterns AI code generators produce: missing Supabase row-level security, secret keys leaked into the client bundle, unauthenticated endpoints, exposed admin routes and boilerplate CORS/CSRF mistakes. There is also an opt-in active Supabase RLS probe that goes past passive recon and actually attempts read-only queries against the Supabase project found in the bundle to confirm whether RLS is enforced — capped at ten requests, 100 ms apart, read-only, and gated behind an explicit ownership attestation with a clear warning that running it against someone else's app may breach their terms of service or unauthorised-access law. Beyond the scanner there is a code-review surface where you paste JavaScript, React, HTML or CSS and get a UAT and best-practice audit with one-click inserts, plus a monitoring tab. It runs as a single HTML file against your own Claude key, and the QA check is free.
Does ChatGPT recommend your AI tool?
If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.
Key Features
Tags
Is Qualmly your tool?
This is the page buyers and AI assistants read when they look up Qualmly. Claim your listing for $19 one-time — no subscription, nothing to cancel — and get a Featured badge, top placement in your category, and a permanent dofollow backlink. Prefer it ongoing? Monthly is one click away on the next page.
Complete Your Security Stack
Other security tools in our catalog:
1Password
Try FreeSecrets and credential manager
Keep API keys and .env secrets out of your repo
Gamma
Try FreeAI presentation builder
Turn ideas into polished decks instantly
AdCreative.ai
Try FreeAI-powered ad creatives
Generate marketing visuals in seconds
💰 Affiliate disclosure: We may earn a commission if you sign up through these links at no extra cost to you.
Stay updated on AI Security & Testing tools — join our weekly newsletter
One concise email with fresh launches, trending picks, and featured standouts.
Alternatives to Qualmly
View all Qualmly alternatives →More AI Security & Testing tools
VibeDoctor
149+ automated security, performance, and quality checks plus ongoing monitoring for AI-built apps
Vulert
Agentless software composition analysis from manifest or SBOM files — no code access, hourly scans, license compliance and container SBOMs.
Guardr
Security and uptime monitoring for client sites — SSL, headers, DNS, exposed files and leaked JS secrets, graded A–F.
Shieldly
AI-graded security analysis for AWS IAM, CloudFormation and resource policies — surfaces wildcards, PassRole risks and privilege escalation paths, with a no-signup analyser and browser-only free tools.
Should I Ship
Free local CLI scan for launch risks in AI-built apps, with a $10 one-time full report
SigmaShake
Runtime guardrails that block dangerous AI agent commands deterministically in about 85ms, with full audit
Agent connectivity: not yet verified