Kavach

Check · Third-party supply chain · default severity high

Third-party script supply chain

What Kavach checks

External scripts your page loads from other companies' servers, and whether they're pinned with Subresource Integrity (SRI).

Why it matters

A third-party script runs with full access to your page. If that vendor is compromised (as in the Polyfill.io attack), your site is too -- and server-side firewalls never see it. SRI makes the browser reject a tampered script.

How an attacker uses it

  1. Attacker compromises a script vendor your site embeds.
  2. The vendor serves malicious JS; with no SRI, the browser runs it.
  3. It skims every form on your page -- logins, card numbers.

How to fix it

Add integrity="sha384-..." and crossorigin to every third-party <script>, self-host critical ones, and drop vendors you don't need.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously