Kavach

Check · Third-party supply chain · default severity medium

Mixed content

What Kavach checks

Resources loaded over plain http:// on an https:// page.

Why it matters

An http:// script or iframe on a secure page can be swapped in transit, undoing the protection of HTTPS; browsers block or warn on it.

How an attacker uses it

  1. Your https page loads one script over http.
  2. An attacker on the network replaces that script in transit.
  3. It runs with full access to your 'secure' page.

How to fix it

Load every script, stylesheet, image and frame over https:// (or use protocol-relative/absolute https URLs).

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously