Check · Browser protection · default severity high
Content Security Policy (CSP)
What Kavach checks
A whitelist of where scripts, styles and images may load from.
Why it matters
The single strongest defense against cross-site scripting (XSS). Without it, one injected <script> can steal every visitor's session and keystrokes.
How an attacker uses it
- Attacker finds a field that echoes input back (search box, comment).
- They submit <script>steal(document.cookie)</script>.
- With no CSP, the browser happily runs that injected script.
- Every visitor's session token is quietly sent to the attacker.
How to fix it
Start with: Content-Security-Policy: default-src 'self'; object-src 'none'; base-uri 'self' -- then tighten.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.