Kavach

Check · Browser protection · default severity medium

Clickjacking protection

What Kavach checks

Stops your site being embedded invisibly inside an attacker's page (X-Frame-Options or CSP frame-ancestors).

Why it matters

Prevents clickjacking, where a user thinks they're clicking an attacker's page but is really clicking 'Confirm transfer' on yours, loaded invisibly on top.

How an attacker uses it

  1. Attacker builds a page: 'Click to win a prize'.
  2. They load YOUR site invisibly in a transparent layer on top.
  3. The victim's click lands on your 'Delete account' / 'Transfer' button.
  4. The victim never saw it -- they thought they clicked the prize.

How to fix it

Add: X-Frame-Options: DENY (or CSP 'frame-ancestors none').

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously