Kavach

Check · Transport security · default severity high

HTTP Strict Transport Security (HSTS)

What Kavach checks

Tells browsers to only ever connect over HTTPS for your domain.

Why it matters

Stops an attacker from quietly downgrading a victim's first connection to http:// and stealing the session (SSL-strip).

How an attacker uses it

  1. Victim types 'yoursite.com' (no https://) into the browser.
  2. Attacker on the network intercepts that first plain-http request.
  3. Instead of letting it upgrade to https, attacker keeps it on http.
  4. Every password and cookie after that flows in clear text.

How to fix it

Add: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously