Kavach

Check · Browser protection · default severity low

Permissions-Policy

What Kavach checks

Declares which browser features (camera, mic, geolocation) your site may use.

Why it matters

Limits what injected or embedded code can switch on without the user realising.

How an attacker uses it

  1. Injected or embedded code asks for the camera or location.
  2. With no policy, the browser lets it try.

How to fix it

Add: Permissions-Policy: geolocation=(), microphone=(), camera=()

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously