Kavach

Check · Transport security · default severity high

HTTP redirects to HTTPS

What Kavach checks

Whether a plain http:// request is sent straight to https://.

Why it matters

If port 80 serves content instead of redirecting, every typed-in or old link keeps users on an unencrypted connection.

How an attacker uses it

  1. Victim types yoursite.com without https://.
  2. Your server answers over plain HTTP instead of redirecting.
  3. The whole session happens unencrypted.

How to fix it

Answer every http:// request with a 301 redirect to the https:// URL (and enable HSTS once that works).

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously