How to tell if a website was built with Lovable
Lovable is the most common AI app builder on the web, and it leaves more fingerprints than most. Here is every one we know of, and a 30-second check.
To tell if a website was built with Lovable, check the address first, then the page source. Lovable, the AI app builder that was called GPT Engineer until late 2024, publishes projects on its own domains and adds its own scripts and tags. Most Lovable sites carry at least one of them, even on a custom domain.
Below is every Lovable fingerprint we use in Kitsuvo's detector, roughly from strongest to weakest, followed by a quick way to check any page yourself.
Lovable's hosting domains
When someone presses Publish in Lovable without connecting their own domain, the site goes live on one of these:
*.lovable.app: published projects*.lovableproject.com: project previews*.gptengineer.app: older projects from the GPT Engineer days*.lovable.runand*.lovable.sh: other Lovable-run hosts
An address on any of these answers the question. It is the strongest single signal there is.
Scripts and markup in the source
On a custom domain the address tells you nothing, so look at the code. Open the source (Ctrl+U, or Option+Command+U on a Mac) and search for:
| Search for | What it is | Strength |
|---|---|---|
data-lov-id | Attributes from Lovable's component tagger, one per element | Very strong |
gptengineer.js or cdn.gpteng.co | The Lovable runtime script | Very strong |
lovable-tagger | The build plugin that adds the tagger | Very strong |
/lovable-uploads/ | Image paths for files uploaded in the Lovable editor | Strong |
/~flock.js | A Lovable runtime script on published sites | Strong |
Edit with Lovable | The badge Lovable shows on free projects | Strong |
Many Lovable sites render with JavaScript, so the raw source can be nearly empty. If your search finds nothing, press F12 and search the Elements panel, which shows the page after its scripts have run.
Default meta tags and share images
New Lovable projects ship with placeholder metadata, and plenty of people never change it:
- A meta description of
Lovable Generated Project
<meta name="author" content="Lovable"><meta name="twitter:site" content="@lovable">- An Open Graph share image served from
lovable.dev, often a generic Lovable card - A tab title of
Lovable App
, or the Vite defaultVite + React + TS
Each of these names Lovable outright, so a single one is good evidence. Paste the link into a messaging app: if the preview shows a Lovable card instead of the site's own image, you have your answer without opening the source at all.
A 30-second check in the console
For a faster test, open the developer tools (F12), go to the Console tab and paste this. It only reads the page and changes nothing:
[...document.querySelectorAll('script[src], img[src]')].map(e => e.src)
.filter(s => /gpteng|lovable/i.test(s))
.concat(document.querySelector('[data-lov-id]') ? ['data-lov-id present'] : [])
An empty list [] means none of these fingerprints is on the page. Anything else is a hit, and the output tells you which.
Only paste code you understand into a console, and never on a page that asks you to. That request is a common scam trick.
Style signs that point to Lovable
Lovable generates React with Tailwind CSS and the shadcn/ui components, so its sites share a look: rounded cards, soft shadows, a gradient hero, and class names like text-muted-foreground in the source. Toast notifications from the Sonner library are common too.
These are weak signs. Bolt, v0 and many human developers use exactly the same stack. They support a fingerprint; they do not replace one. Our builder fingerprint guide shows how to tell Lovable apart from the others.
When a Lovable site shows no fingerprints
Lovable lets people sync their project to GitHub and host it anywhere. Some fingerprints, like the component tagger, only appear in preview builds. Others disappear when someone tidies up the metadata. A determined owner can remove them all.
In that case, the honest result is "possibly vibe coded" or "no strong AI signs", depending on what is left. A detector that claims certainty on a clean site is guessing.
Checking for Lovable automatically
Kitsuvo is our no-AI web browser for Mac and Windows. It runs every check on this page, and the equivalent checks for about 20 other builders, on each page you open. When it finds Lovable it says so in the address bar, with a score and the exact evidence it matched. It runs on your computer and is free.
Questions people ask
Is lovable.app safe?
The domain belongs to Lovable and hosts sites its users publish, so its safety depends on the individual site, the same as any hosting provider. Most are ordinary projects. Be cautious if a lovable.app page claims to be a bank, a delivery company or another brand and asks you to sign in, because scammers use builder hosting too.
What is gptengineer.js?
It is the Lovable runtime script, loaded from cdn.gpteng.co. The name comes from GPT Engineer, Lovable's name before it rebranded. Finding it in a page's source is strong evidence the page was built with Lovable.
Can I tell if a Lovable site uses a custom domain?
Often, yes. The address will not help, but scripts like gptengineer.js, image paths under /lovable-uploads/ and default meta tags often remain. Check the page source and the share image.