Kavach

Check · Browser protection · default severity high

Content Security Policy (CSP)

What Kavach checks

A whitelist of where scripts, styles and images may load from.

Why it matters

The single strongest defense against cross-site scripting (XSS). Without it, one injected <script> can steal every visitor's session and keystrokes.

How an attacker uses it

  1. Attacker finds a field that echoes input back (search box, comment).
  2. They submit <script>steal(document.cookie)</script>.
  3. With no CSP, the browser happily runs that injected script.
  4. Every visitor's session token is quietly sent to the attacker.

How to fix it

Start with: Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'self' -- then tighten.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously