OpzyAI is a security scanner for apps built with AI coding tools like Cursor, Lovable, v0 and Bolt. Paste a URL for a free Vibe Check — a Launch Readiness score that catches leaked API keys, exposed source and config, and the security holes AI quietly ships — with plain-English fixes. Connect your repo for deep scans of secrets, dependencies and code, then get fixes your AI editor applies for you over MCP — exact dependency upgrades and secret-rotation runbooks.
Hi Product Hunt 👋
I build apps with AI coding tools every day. They're incredible — and they also hardcode API keys into client bundles, commit .env files, and leave source maps on production domains. I know because I kept doing it myself, and because the first thing I built to check for it kept finding the same five mistakes in almost every vibe-coded app I scanned.
So I turned it into OpzyAI:
🔍 Free Vibe Check — paste your live URL, get a 0–100 Launch Readiness score in ~15 seconds. No account, no install. It's passive: it only looks at what your site already shows every visitor — leaked keys in the JS bundle (OpenAI, Anthropic, Stripe, Supabase), exposed .env / .git / source maps, missing security headers.
🛠️ Fixes, not jargon — every finding is plain English: what's exposed, why it matters, and a fix you can paste straight into Cursor or Claude Code.
🏅 Badge — score 80+ and you get an embeddable "Vibe Check ✓" badge for your README.
🤖 MCP — run it from inside your editor. The free local server (npx -y @opzyai/mcp) checks your working tree for secrets before you push. The Pro server deep-scans your repo (dependency CVEs, SAST, git-history secrets) and hands your agent the exact fix to apply — a precise package.json upgrade or a key-rotation runbook. OpzyAI never writes to your repo; your editor applies, you review.
Honest scope note: a passive scan can't see server-side bugs — a clean score means "not leaking the obvious stuff," not "secure." That's what the deep repo scan is for (Pro, €29/mo, 14-day trial).
Scan your app and tell me what it gets wrong — false positives are bugs and I'll fix them same-day: https://www.opzyai.com/scan?utm_...
Report
Ran the Vibe Check on a Lovable app and it actually caught an exposed Supabase key I'd forgotten about. The plain-English fix suggestions were clear enough that I could hand them to my non-technical cofounder.
Report
Maker
@koglu5218 oh this is great to hear. a forgotten supabase key on a lovable app is basically the exact reason this exists. and "could hand them to my non-technical cofounder" might be the best thing anyone's said about the plain-english findings. thanks for actually running it and coming back to tell me!
Report
No reviews yetBe the first to leave a review for OpzyAI
Ran the Vibe Check on a Lovable app and it actually caught an exposed Supabase key I'd forgotten about. The plain-English fix suggestions were clear enough that I could hand them to my non-technical cofounder.
@koglu5218 oh this is great to hear. a forgotten supabase key on a lovable app is basically the exact reason this exists. and "could hand them to my non-technical cofounder" might be the best thing anyone's said about the plain-english findings. thanks for actually running it and coming back to tell me!