Check · Browser protection · default severity medium
CSP strength
What Kavach checks
Whether the CSP you have actually blocks injected scripts.
Why it matters
A CSP with 'unsafe-inline' or 'unsafe-eval' in script-src, or a wildcard source, lets XSS through almost as if there were no policy at all.
How an attacker uses it
- Attacker injects an inline <script> through a comment field.
- Your CSP says script-src 'unsafe-inline', so the browser runs it.
- The 'protection' header never protected anything.
How to fix it
Remove 'unsafe-inline'/'unsafe-eval' from script-src (use nonces or hashes), drop wildcards, add object-src 'none' and base-uri 'self'. Roll out with Content-Security-Policy-Report-Only first.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.