Check · Third-party supply chain · default severity medium
Mixed content
What Kavach checks
Resources loaded over plain http:// on an https:// page.
Why it matters
An http:// script or iframe on a secure page can be swapped in transit, undoing the protection of HTTPS; browsers block or warn on it.
How an attacker uses it
- Your https page loads one script over http.
- An attacker on the network replaces that script in transit.
- It runs with full access to your 'secure' page.
How to fix it
Load every script, stylesheet, image and frame over https:// (or use protocol-relative/absolute https URLs).
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.