Kavach

Check · Browser protection · default severity medium

CSP strength

What Kavach checks

Whether the CSP you have actually blocks injected scripts.

Why it matters

A CSP with 'unsafe-inline' or 'unsafe-eval' in script-src, or a wildcard source, lets XSS through almost as if there were no policy at all.

How an attacker uses it

  1. Attacker injects an inline <script> through a comment field.
  2. Your CSP says script-src 'unsafe-inline', so the browser runs it.
  3. The 'protection' header never protected anything.

How to fix it

Remove 'unsafe-inline'/'unsafe-eval' from script-src (use nonces or hashes), drop wildcards, add object-src 'none' and base-uri 'self'. Roll out with Content-Security-Policy-Report-Only first.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously