Kavach

Check · Operational hygiene · default severity low

Responsible disclosure (security.txt)

What Kavach checks

A /.well-known/security.txt that tells researchers how to report a vulnerability to you.

Why it matters

Without it, a researcher who finds a bug has no clear, private way to reach you -- so bugs get dropped publicly or sold instead.

How an attacker uses it

  1. A researcher finds a real bug in your site.
  2. They can't find a contact, so they post it publicly.

How to fix it

Publish /.well-known/security.txt with a Contact: line and an Expires: date (RFC 9116).

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously