Kavach

Check · Transport security · default severity high

TLS protocol strength

What Kavach checks

Which TLS versions the server negotiates and still accepts.

Why it matters

TLS 1.0/1.1 are broken and deprecated. Accepting them lets an attacker force a weak, decryptable connection (downgrade attack).

How an attacker uses it

  1. Attacker on the network blocks the strong TLS handshake.
  2. Server falls back to TLS 1.0/1.1 because it still allows them.
  3. Known weaknesses in old TLS let the attacker read the traffic.

How to fix it

Allow only TLS 1.2 and 1.3; disable TLS 1.0/1.1 and weak ciphers.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously