✍️Writing & Content58🎨Image Generation71🎬Video & Animation120🎵Audio & Music100💬Chatbots & Assistants109💻Coding & Development444📈Marketing & SEO197Productivity401🎯Design & UI/UX120📊Data & Analytics126📚Education & Research55💼Business & Finance174🏥Healthcare & Wellness22🔍Search & Knowledge20🤖AI Agent Infrastructure208🛡️AI Security & Testing32🧊3D & Spatial22🔎SEO Tools113🏡Real Estate7🗃️Data Extraction104🧠ADHD & Focus Tools11🔬Research & Academia45🧩LLM APIs & Models34⚙️Automation & Workflows45🔐Security & Privacy31📊Analytics & BI55⚖️Legal & Contracts14
Listed in AI Security & Testing with 39 other toolsPart of 3449+ curated AI tools on AISO
Qualmly logo

Qualmly

AI security and QA reviewer for vibe-coded apps — checks for leaked keys, missing Supabase RLS and exposed routes in 30 seconds.

freeThe QA check is free and runs against your own Claude API key; the UAT and code-quality surface is in free beta. No paid tier is published at the time of verification.View full pricing →

About Qualmly

Qualmly is an AI reviewer aimed specifically at applications shipped out of Lovable, Bolt, v0, Cursor, GitHub Copilot, Claude Code, Windsurf, Replit and Webflow — the class of app where nobody on the team is necessarily an engineer and the failure modes are consistent enough to check for by name. You paste an app URL, or the raw HTML when the app sits behind a login or blocks crawlers, pick the app type, and it returns findings across eight test categories in plain English in about thirty seconds. The Vibe-Coded App preset targets the specific patterns AI code generators produce: missing Supabase row-level security, secret keys leaked into the client bundle, unauthenticated endpoints, exposed admin routes and boilerplate CORS/CSRF mistakes. There is also an opt-in active Supabase RLS probe that goes past passive recon and actually attempts read-only queries against the Supabase project found in the bundle to confirm whether RLS is enforced — capped at ten requests, 100 ms apart, read-only, and gated behind an explicit ownership attestation with a clear warning that running it against someone else's app may breach their terms of service or unauthorised-access law. Beyond the scanner there is a code-review surface where you paste JavaScript, React, HTML or CSS and get a UAT and best-practice audit with one-click inserts, plus a monitoring tab. It runs as a single HTML file against your own Claude key, and the QA check is free.

Does ChatGPT recommend your AI tool?

If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Key Features

Scans a live app URL or pasted HTML across eight test categories
Vibe-coded preset for leaked client keys, missing RLS and open admin routes
Opt-in active Supabase RLS probe, read-only and rate-capped
Explicit ownership attestation required before active probing
Paste-code review with UAT scenarios and one-click fixes
Runs on your own Claude key, no signup needed

Tags

vibe-codingsupabase-rlssecurity-scancode-reviewlovable
🏷️

Is Qualmly your tool?

This is the page buyers and AI assistants read when they look up Qualmly. Claim your listing for $19 one-time — no subscription, nothing to cancel — and get a Featured badge, top placement in your category, and a permanent dofollow backlink. Prefer it ongoing? Monthly is one click away on the next page.

Stay updated on AI Security & Testing tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Alternatives to Qualmly

View all Qualmly alternatives →

More AI Security & Testing tools

Agent connectivity: not yet verified