Skip to content

Builder-fingerprint checker

Was this website vibe coded?

Paste a public URL and Vibe Check looks for supported builder fingerprints in hosting, scripts and markup. It shows the evidence behind the result and says when attribution is not possible. To inspect selected security signals instead, use Vibe Scan.

Indicative attribution from public markers. No fingerprint is not proof that a site was built without AI.

Interactive check

Read the public fingerprints

Enter a public URL. The result names a builder only when a supported signal is present and shows the matching evidence.
Builder evidence
Usually around ten seconds · read-only
Public URL

Start with the address in question

We inspect supported signals in public hosting, scripts and markup. The result shows exactly what informed the reading.

Free to runEvidence shownPublic information only

We keep only your name, email and the URL you check. The result is generated live, shown only to you, and never stored on our servers.

The checker reads public page information. Treat the result as an indicative technical observation, not a statement about authorship, quality or security.

How it works

Different builders leave different levels of evidence

These are the platform signals the checker considers. For a manual view, read the seven signs of a vibe-coded site.

Lovable

A comparatively visible fingerprint

A tracking script or platform hosted domain can provide a strong public signal when it has not been removed.

cdn.gpteng.co/gptengineer.jslovable.app hostinglovable-uploads paths

Bolt.new

Hosting and build artefacts

Platform hosting and selected StackBlitz or default Vite artefacts can support an indicative result.

bolt.host hostingStackBlitz artefactsVite scaffold markers

Replit

Platform domains and banners

Hosted domains and a development banner can remain visible when a project is moved into production.

replit.app / repl.coReplit development banner

Base44

Hosted application markers

The platform domain and selected public API endpoints can identify an application that remains on the hosted platform.

base44.app hostingBase44 API endpoints

v0, Cursor & Claude Code

Often little or no reliable fingerprint

Code first tools can produce ordinary deployable code. Markup patterns are weaker evidence and the checker says when confidence is low.

shadcn/ui defaultsTailwind patternsoften no fingerprint

Honest limits

Where the checker goes quiet

A useful attribution tool must be explicit about evidence it cannot see and conclusions it cannot support.

No evidence is not negative evidence

When supported markers are absent, Vibe Check reports that it found no fingerprint. It does not guess from generic design patterns simply to produce a more dramatic result.

“Vibe coded” is also not a quality judgement. A well reviewed AI built site can be more robust than poorly maintained hand written software.

The useful follow-up

Knowing the builder is different from knowing the risk

If a public fingerprint is present, the next question is whether the deployed application exposes credentials, data or unsafe defaults.

Vibe Check

Builder attribution

Shows selected public fingerprints and the evidence supporting an indicative builder result.

About the evidence

What a fingerprint can and cannot prove

Platform markers, code-first blind spots and why builder attribution is separate from quality or security.

Ask the second question

Found a fingerprint? Check the public security surface next.

Use Vibe Scan for an automated public assessment, or talk to us if the application needs a source level review and remediation plan.
Builder evidence · security is a separate assessment