Check · Transport security · default severity critical
Served over HTTPS
What Kavach checks
Whether traffic is encrypted end-to-end with TLS.
Why it matters
Without HTTPS, anyone on the network path -- cafe wifi, your ISP, a hop in between -- can read passwords and session cookies in plain text and impersonate your users.
How an attacker uses it
- Attacker joins the same wifi / sits on a network hop.
- Victim loads your site over http:// (no padlock).
- Attacker reads the login form and session cookie in clear text.
- Attacker replays the cookie and is now logged in as the victim.
How to fix it
Install a TLS certificate (free via Let's Encrypt) and redirect all http:// traffic to https://.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.