Kavach

Check · Browser protection · default severity low

MIME-sniffing protection

What Kavach checks

Stops browsers from guessing a file's type and running an upload as script.

Why it matters

Blocks attacks where a user-uploaded 'image' is sniffed and executed as JavaScript.

How an attacker uses it

  1. Attacker uploads a file that is really JavaScript, named like an image.
  2. Without nosniff, the browser guesses its type and executes it.

How to fix it

Add: X-Content-Type-Options: nosniff

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously