Test your vibe-coded app before your users do
Vibe coding means describing what you want and letting an AI write the app. It is fast, and it moves the risk: you often ship code you did not read. If you want to test a vibe coded app, you need a method that does not depend on understanding the code. This guide is for solo creators and small teams. You get the usual failure areas, a 15-step plan, and a way to read a GO / NO-GO verdict.
What typically breaks in AI-built apps
These are general patterns, not measurements.
- Authentication. Sign-up, email confirmation, password reset and sign-out are often only tried once, by the author.
- Forms. They look complete but may not save, validate or confirm.
- Differences between preview and production. Addresses, keys and redirects change when you publish.
- Mobile layout. Built and checked on a laptop.
- Accessibility. Contrast, labels, keyboard access and image text.
- Error states. Blank screens or raw technical messages.
- Exposed information. Debug output, sample data or keys visible to visitors.
- Compliance. Cookies and tracking without notice.
A 15-step plan to check a vibe coded app
- Write down in one sentence what a visitor must be able to do.
- Publish to the real public address.
- Open it in a private window.
- Check laptop and phone.
- Click every link and button.
- Register with a fresh email.
- Sign out, sign in, test a wrong password and a password reset.
- Complete the main journey from start to finish.
- Submit every form empty, long and unusual.
- Use the keyboard only.
- Check contrast and image text.
- Visit a missing address and reload a deep page.
- Look for debug messages, test data and exposed keys in what you can see.
- Read the cookie and privacy notices.
- Run an independent read-only test and keep the report.
Steps 1 to 14 you can do by hand in an hour or so. Step 15 repeats them from outside with evidence.
How to read a GO / NO-GO
- GO: no blocking finding was seen on the pages tested. It is not proof the app is free of defects.
- NO-GO: at least one blocking finding, with evidence such as a screenshot. Fix those first.
- INCONCLUSIVE (INCONCLUSIF in the API): the test could not judge, for example because access stopped at a login. Give a test account and run again.
- GO SOUS CONDITIONS (API): passable, with findings to address.
Findings are ranked by severity from S1 to S4. Start with S1 and S2, redeploy, and run the same test again to compare with the previous run.
Where your tool's own guide helps
Each tool has its own habits. Pick yours:
- Lovable, also when a Lovable app is not working
- Bolt
- Replit
- Hercules
- Base44
- v0
- Claude Code
- Claude Cowork
- Cursor or Windsurf
The hub AI app builders lists them all.
What an independent test adds
The assistant that wrote your code knows your intentions, so it tends to check what it meant to build. A separate tool that sees only the published address behaves like a visitor: it does not read your code and does not share the assistant's blind spots. Avalyz proves what it saw; it does not vouch for the rest, and a clean report is not proof that the app has no defects. It is a second pair of eyes, not a substitute for your own judgement.
Test your vibe-coded app with Avalyz
Avalyz tests a web application from the outside, in real browsers, and returns a verdict with evidence. Start free at /banc: paste your app's address, no sign-up, 3 tests a day. Or open https://avalyz.com/essai?url=YOUR_APP_URL with your own address in place of YOUR_APP_URL: it fills in the address and starts the test.
- Read-only by default. By default, nothing is created or changed on your app. Only public addresses are accepted.
- Optional test account. If your app has a login, give a test account: the sign-in form is then the sole form submitted, and the signed-in pages are explored read-only.
- A GO / NO-GO verdict with evidence, findings ranked by severity, and a report you can paste back into vibe-coded so the fix goes to the tool that built the app.
- Plans, in US dollars with no commitment, are on /tarifs; there is also a 14-day trial of the Pro plan with no card.
FAQ
How do I test a vibe coded app without reading the code?
Test it as a visitor: the plan above, plus an independent test of the published address.
How often should I test?
After every deployment. Avalyz can be run by hand, through the API or from CI, and monitoring can be scheduled.
Can an AI test an app built by an AI?
Yes. It is a different AI, independent of the one that wrote your app, and it does not see your code. It is a second pair of eyes, not a substitute for your judgement.
Does a GO mean I can sell?
It means an independent test saw no blocking finding. The decision to show, deliver or sell stays yours.
Does it cover legal compliance?
No. A cookie finding flags a risk; it is not legal advice.