See your website the way a hacker does.
Kavach probes your app like an attacker casing the building — then hands you the diagnosis, not the damage. A plain-English grade and a fix list. Nothing is attacked. Nothing is taken down.
Free public scan · read-only · results in seconds · internal/localhost targets are blocked for safety · exposure checks (.env/.git) unlock after you verify ownership.
🛰 Monitor this site
Kavach re-scans on a schedule and alerts you the moment a deploy opens a hole. Three steps: get a key, prove you own the domain, pick an alert channel.
1 Your API key
Signed in as .
Plan: …
2 Verify you own the domain
Add either of these, then click Check:
3 Alert me on regressions
Payment Page Guardian — authorised script baseline for your checkout pages
Recent alerts
What makes Kavach different
- 🛠 It fixes, not just flagsDetects your stack and hands you copy-paste config (nginx/Apache/Caddy/Express/Cloudflare). Others just say "missing".
- ⚔ It shows the attackEvery weakness expands into the step-by-step exploit it enables — in plain English.
- 🏅 Shareable grade badgeEmbed your live security grade anywhere, like a CI build badge.
- 🛡 Secure by designSSRF-guarded, rate-limited, and it serves the headers it grades.
What Kavach checks
- Encryption (HTTPS/HSTS)Is traffic readable on the wire?
- XSS defense (CSP)Can injected scripts steal sessions?
- ClickjackingCan your buttons be hijacked in a frame?
- Cookie hygieneAre session cookies stealable?
- Info leakageAre you advertising exploitable versions?
- Browser policyReferrer & Permissions hardening.
Secure before it promises security
A scanner that fetches any URL on command is a classic Server-Side Request Forgery weapon. Kavach refuses to touch localhost or internal IPs, re-checks every redirect hop, rate-limits itself, and ships the exact security headers it grades others on. We eat our own cooking.