Built for the wave of Lovable, Bolt, v0, Cursor, and Copilot apps shipping to real users without a senior-eng review.
What it does:
- Drop a live URL — scan public bundle in 30 seconds
- Detects leaked sk_live_ keys, missing Supabase RLS, exposed /admin routes, unverified Stripe webhooks, OWASP Top 10, CWE/SANS Top 25, WCAG 2.2, 12-Factor violations
- Plain-English findings — no signup
Free tier: ad-hoc scans, BYO Claude key, runs entirely in your browser.
Pro tier ($99/yr): weekly auto-rescan + diff email when new findings appear. BYOK so the per-scan compute is ~$0.03/week of YOUR Anthropic credit.
Open source (MIT). Single HTML file. Your key never leaves your machine.
47 vibe-coded apps audited so far → 6 had live Stripe keys → all disclosed before launch.
Comments, support and feedback
About this launch
Qualmly was launched by DarkPixel Consulting Inc. in May 12th 2026.
- 0Upvotes
- 1221Impressions
- #20Week rank



