✍️Writing & Content29🎨Image Generation35🎬Video & Animation70🎵Audio & Music53💬Chatbots & Assistants46💻Coding & Development222📈Marketing & SEO70Productivity173🎯Design & UI/UX62📊Data & Analytics54📚Education & Research28💼Business & Finance65🏥Healthcare & Wellness18🔍Search & Knowledge15🤖AI Agent Infrastructure85🛡️AI Security & Testing11🧊3D & Spatial19🔎SEO Tools18🏡Real Estate4🗃️Data Extraction17🧠ADHD & Focus Tools9
Listed in AI Security & Testing with 11 other toolsPart of 1248+ curated AI tools on AISO
Qualmly logo

Qualmly

AI security and QA reviewer for vibe-coded apps — checks for leaked keys, missing Supabase RLS and exposed routes in 30 seconds.

freeThe QA check is free and runs against your own Claude API key; the UAT and code-quality surface is in free beta. No paid tier is published at the time of verification.View full pricing →

Visit Qualmly

https://qualmly.dev

About Qualmly

Qualmly is an AI reviewer aimed specifically at applications shipped out of Lovable, Bolt, v0, Cursor, GitHub Copilot, Claude Code, Windsurf, Replit and Webflow — the class of app where nobody on the team is necessarily an engineer and the failure modes are consistent enough to check for by name. You paste an app URL, or the raw HTML when the app sits behind a login or blocks crawlers, pick the app type, and it returns findings across eight test categories in plain English in about thirty seconds. The Vibe-Coded App preset targets the specific patterns AI code generators produce: missing Supabase row-level security, secret keys leaked into the client bundle, unauthenticated endpoints, exposed admin routes and boilerplate CORS/CSRF mistakes. There is also an opt-in active Supabase RLS probe that goes past passive recon and actually attempts read-only queries against the Supabase project found in the bundle to confirm whether RLS is enforced — capped at ten requests, 100 ms apart, read-only, and gated behind an explicit ownership attestation with a clear warning that running it against someone else's app may breach their terms of service or unauthorised-access law. Beyond the scanner there is a code-review surface where you paste JavaScript, React, HTML or CSS and get a UAT and best-practice audit with one-click inserts, plus a monitoring tab. It runs as a single HTML file against your own Claude key, and the QA check is free.

Key Features

Scans a live app URL or pasted HTML across eight test categories
Vibe-coded preset for leaked client keys, missing RLS and open admin routes
Opt-in active Supabase RLS probe, read-only and rate-capped
Explicit ownership attestation required before active probing
Paste-code review with UAT scenarios and one-click fixes
Runs on your own Claude key, no signup needed

Tags

vibe-codingsupabase-rlssecurity-scancode-reviewlovable
🏷️

Is this your tool?

Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.

Claim Now →

ChatGPT already recommends Qualmly. Does it recommend yours?

If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Stay updated on AI Security & Testing tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Agent connectivity: not yet verified