For Lovable, Bolt, v0 & Replit Builders
Built it with an AI tool? Check what it left exposed.
AI builders ship a working app in an afternoon, and the same handful of mistakes with it: a secret key in the JavaScript, a database table anyone can read, source maps in production, placeholder copy on the live page. SiteAssay checks for all of them from the outside, the way anyone else would find them.
- 3
- Free checkers for the most common AI-builder mistakes, with no account
- 0
- Writes to your backend. Every probe is a read-only request
- $19
- For the full report on one site, with every finding and its fix
- 48
- Specialised checks behind the full report, each against a published standard
The mistakes AI builders make most
Each one is visible from outside without any access to the code, which is exactly why it matters.
Secrets in the bundle
Stripe, OpenAI, AWS and other secret keys found in the JavaScript every visitor downloads, told apart from the publishable keys that are meant to be there.
Check freeA database anyone can read
Supabase tables with row-level security off, and Firebase or Convex backends with no access rules, confirmed with a read-only request.
Check freeSource maps in production
Map files that hand anyone the original source of the app, comments and all.
Check freeLeft-on debug surfaces
A public .env or .git folder, debug pages and open API explorers, each confirmed by what the response contains rather than its status code.
Speaks your builder's language
Fixes you can paste back into the assistant that built it.
SiteAssay recognises the builder and the host, so the report does not tell a Lovable user to edit an nginx config. Where a fix exists, the full report gives you the prompt to paste into your coding assistant, with your domain already filled in.
See a sample report- Builder and host, both detected
- Lovable, Bolt, v0, Replit or Base44, on Vercel, Netlify, Replit or Cloudflare.
- Copy-ready prompts
- The fix written as an instruction for the assistant, not a lecture on server configuration.
- Re-check after the fix
- Run it again and see the finding clear before you announce the launch.
What else the full report checks
The rest of a launch checklist, measured rather than remembered.
Placeholder copy
Lorem ipsum, TODO notes and "your text here" left on the live page.
API exposure
GraphQL introspection left on and CORS policies that let any site read responses.
Security headers
HSTS, Content-Security-Policy and the redirect to HTTPS that most builders leave unset.
Speed and SEO basics
Core Web Vitals, a title and description, a sitemap, and whether search engines can index the page at all.
Questions from people about to launch
Does the database check read my data?
Only enough to prove the point. It sends the read-only request your public key already allows, asks each common table for a single row, and never writes, updates or deletes anything. For Firebase it asks for key names only, never values.
What is the difference between the free checkers and the full report?
Each free checker runs one check and shows the result. The full report runs every check on the site, explains each finding in plain words, and gives you the fix or the prompt to paste for it.
I build these sites for clients. Is there a plan for that?
Yes. A plan lets you audit every site before handover and find local businesses whose sites need the same work, with the report in your own name on Pro and above.
Check it before somebody else does
Run the free checkers now, buy the full report on one site for $19, or start a 7-day free trial if you build sites for clients.