Kavach

Check · Browser protection · default severity high

Cookie hygiene

What Kavach checks

Session cookies should carry HttpOnly, Secure and SameSite flags.

Why it matters

HttpOnly stops JavaScript (and thus XSS) from reading the cookie; Secure keeps it off plain http; SameSite blunts CSRF. Missing flags are the most common route to stolen sessions.

How an attacker uses it

  1. A single XSS hole lets attacker run JavaScript on your page.
  2. Without HttpOnly, that script reads document.cookie directly.
  3. The session cookie is shipped to the attacker's server.
  4. They paste it into their browser and are logged in as the user.

How to fix it

Set every session cookie with: HttpOnly; Secure; SameSite=Lax

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously