Kavach

Check · Transport security · default severity critical

TLS certificate validity

What Kavach checks

Whether the certificate is trusted by browsers and matches the hostname.

Why it matters

An invalid or mismatched certificate lets an attacker impersonate your site, and throws the scary 'Not secure' warning that scares real users away.

How an attacker uses it

  1. Attacker sets up a lookalike server for your domain.
  2. With no valid cert, the browser can't tell real from fake.
  3. Victim's traffic is silently decrypted and modified in transit.

How to fix it

Install a valid certificate from a trusted CA (free via Let's Encrypt) covering this exact hostname, and keep the chain complete.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously