Skip to content

Free vibe code checker

Was this website vibe coded?

Paste a public URL. Vibe Check reads supported hosting, selected same origin scripts and stylesheets, first party build statements, interface cues and copy present in the public HTML.

The result separates overall AI build indicators from provider attribution. No public evidence does not prove that a site was built without AI.

Interactive check

Check a public website

Enter the public URL. The result groups declared use, build traces, interface patterns and copy patterns, then reports provider attribution separately.
Public AI build check
Waiting for URL
https://

The check usually takes about ten seconds, uses public information only and asks you to confirm authorisation next.

The checker reads public page information. Its result does not establish authorship, quality or security.
VibeZero credential
SMB1001 SilverCyberCert certified.
Result basis
Evidence shownSupported markers appear in the result.
Check scope
Read onlyPublic page, selected scripts and stylesheets from the same origin. No forms or private areas.

Supported evidence

Signals differ by builder and deployment

Hosting and runtime markers can identify a provider. Generic framework patterns cannot identify one or produce a likely overall result alone. Several evidence groups can still support an overall assessment. For a manual view, read the seven signs of a vibe coded site.

Lovable

Runtime and hosting markers

A Lovable hosted address can support a strong provider association. Script references, build tags and unsigned public trust files are shown as supporting claims, not verified build history.

lovable.appcdn.gpteng.cobuild tagasset path

Bolt.new

Provider hosted domains

A Bolt hosted address identifies hosting, not how the application was built. Existing code can be imported and published there. Build declarations and other public evidence are assessed separately.

bolt.hostbolt.newgeneric stack is context

Replit

Platform domains and attribution

A Replit address identifies hosting, not whether an agent wrote the application. A visible attribution is reported separately as a public claim.

replit.apprepl.coreplit.devReplit attribution

Base44

Hosted application and SDK references

A Base44 address identifies hosting. Its SDK identifies a backend service reference. Neither establishes who built the interface or whether AI was used.

base44.app@base44/sdk

Other hosted builders

Provider hosted domains

Google AI Studio, Manus, Mocha and Anything publish to their own domains, so an address on one of those is a strong public association with that platform. A Hugging Face Space serves whatever its owner pushes, so it identifies the hosting only.

ai.studiomanus.spacemocha.appcreated.apphf.space is hosting

No code platforms

Platforms reported separately

Bubble, Softr, Glide, Carrd, Wix, Squarespace, Webflow, Framer, Shopify and WordPress are reported separately as website platforms. Identifying a platform does not establish whether AI contributed to the design, copy or code.

bubbleapps.iosoftr.appglide.pagecarrd.co

Code agents

Declarations and public build traces

The checker can report a first party statement that AI was used, public generator metadata, build comments and corroborated project artefacts. It keeps that overall assessment separate from naming a code agent.

declared useClaude CodeCodexCursorCopilotproject artefacts

Result boundaries

What the two results can support

The overall assessment and provider attribution answer different questions. Both remain indicative.

Several evidence groups

An indicative overall assessment

Different groups of public indicators can support an indicative AI assisted build result. Related design and library cues count together. They do not reconstruct the full development history.

No material pattern found

A quiet result

Markers can be removed, and code first tools may leave none. A common library, design treatment or writing habit cannot produce a likely result by itself.

A separate question

Quality and security

A builder fingerprint does not show whether the application was reviewed or secured. Vibe Scan checks selected public security signals.

About the evidence

What public evidence can and cannot prove

First party statements, provider markers, code first blind spots and why build evidence is separate from quality or security.

A lovable.app address is a strong public association with Lovable. A reference to its gptengineer.js script or an unsigned public trust file is supporting evidence that can be copied. If the markers have been removed or the code is hosted elsewhere, attribution becomes less certain.

Manual review

Need more than public evidence?

Public build evidence cannot verify source code, access control or delivery quality. The manual audit covers the deeper review and remediation path.
Start with public evidence. Use manual review when the question is deeper.