Kavach

Check · Transport security · default severity critical

Served over HTTPS

What Kavach checks

Whether traffic is encrypted end-to-end with TLS.

Why it matters

Without HTTPS, anyone on the network path -- cafe wifi, your ISP, a hop in between -- can read passwords and session cookies in plain text and impersonate your users.

How an attacker uses it

  1. Attacker joins the same wifi / sits on a network hop.
  2. Victim loads your site over http:// (no padlock).
  3. Attacker reads the login form and session cookie in clear text.
  4. Attacker replays the cookie and is now logged in as the victim.

How to fix it

Install a TLS certificate (free via Let's Encrypt) and redirect all http:// traffic to https://.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously