Built your app with AI? Hosted it? Is it actually secure?
Lovable, Bolt, v0, Replit, Cursor or Claude Code wrote the code and shipped it. Nobody reviewed it. Kavach sees your site the way a hacker does, grades it in plain English, and hands you fixes to paste straight back into your AI tool. Nothing is attacked. Nothing is taken down.
Free public scan · read-only · results in seconds · internal/localhost targets are blocked for safety · exposure checks (.env/.git) unlock after you verify ownership.
🛰 Monitor this site
Kavach re-scans on a schedule and alerts you the moment a deploy opens a hole. Three steps: get a key, prove you own the domain, pick an alert channel.
1 Your API key
Signed in as .
Plan: …
2 Verify you own the domain
Add either of these, then click Check:
3 Alert me on regressions
Payment Page Guardian — authorised script baseline for your checkout pages
Recent alerts
Reviewed? Secure? Still in doubt?
An AI assistant optimises for "it works". These are the defaults it leaves behind, and every one of them is visible from outside. Read the full guide →
- 🌐 The API answers any websiteCORS opened to every origin so the demo worked. Any page on the internet can now call your API as your users.
- 🍪 Login cookies without safety flagsNo HttpOnly, Secure or SameSite. One injected script or one http:// link steals the session.
- 🧱 No Content-Security-PolicyAlmost no AI builder emits one. It is the control that stops injected scripts even when the code has a bug.
- 🔑 .env or .git shipped with the buildThe deploy copied the whole folder. Secrets and full source history are one URL away. Checked for verified owners, never stored.
- 🏷 Headers advertise the framework versionHosting defaults tell an attacker exactly which known exploits to try.
- ✉️ Your domain can be spoofedThe app sends email but nobody set SPF, DKIM or DMARC. Phishing "from you" looks real.
Scan the code, not just the site
Zip the project and upload it. Kavach streams through every file, in any language, and flags string-built SQL, shell commands with user input, unescaped output, credentials in source, wide-open CORS, disabled TLS checks, unsafe deserialisation, debug left on, and Firebase or Supabase rules that let everyone in. The archive is deleted the moment the scan ends. You get a graded fix report and a remediation prompt to paste straight back into the AI that wrote the code.
What makes Kavach different
- 🛠 It fixes, not just flagsDetects your stack and hands you copy-paste config (nginx/Apache/Caddy/Express/Cloudflare). Paste it back into the AI that built the app. Others just say "missing".
- ⚔ It shows the attackEvery weakness expands into the step-by-step exploit it enables — in plain English.
- 🏅 Shareable grade badgeEmbed your live security grade anywhere, like a CI build badge.
- 🛡 Secure by designSSRF-guarded, rate-limited, and it serves the headers it grades.
What Kavach checks
- Encryption (HTTPS/HSTS)Is traffic readable on the wire?
- XSS defense (CSP)Can injected scripts steal sessions?
- ClickjackingCan your buttons be hijacked in a frame?
- Cookie hygieneAre session cookies stealable?
- Info leakageAre you advertising exploitable versions?
- Browser policyReferrer & Permissions hardening.
Secure before it promises security
A scanner that fetches any URL on command is a classic Server-Side Request Forgery weapon. Kavach refuses to touch localhost or internal IPs, re-checks every redirect hop, rate-limits itself, and ships the exact security headers it grades others on. We eat our own cooking.