Check · Transport security · default severity high
HTTP redirects to HTTPS
What Kavach checks
Whether a plain http:// request is sent straight to https://.
Why it matters
If port 80 serves content instead of redirecting, every typed-in or old link keeps users on an unencrypted connection.
How an attacker uses it
- Victim types yoursite.com without https://.
- Your server answers over plain HTTP instead of redirecting.
- The whole session happens unencrypted.
How to fix it
Answer every http:// request with a 301 redirect to the https:// URL (and enable HSTS once that works).
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.