Kavach

Code Scan · static analysis for any language

Upload the code. Get the fix list.

Zip the project folder and drop it here. Kavach streams through every file for the mistakes that AI assistants and busy humans make most: SQL built from strings, shell commands with user input, unescaped output, credentials in source, wide-open CORS, disabled TLS checks, unsafe deserialisation, debug left on, and Firebase or Supabase rules that let everyone in. Works on React, Node, PHP, Python, Java, Kotlin, C#, Go, Ruby, Docker, Terraform and config files, up to hundreds of thousands of lines.

1. Sign in

2. Upload a zip

Previous scans

How it works

  1. UploadThe zip is written once to an isolated upload area and queued. It is never extracted.
  2. Stream and matchA worker reads each file straight from the archive, skips vendored and minified code, and runs language-aware rules with a cheap prefilter so large repositories finish in seconds to a few minutes.
  3. Report and deleteFindings are grouped, graded and mapped to CWE/OWASP; the archive is deleted whatever the outcome.
  4. Fix with your AI toolCopy the remediation prompt into the assistant that wrote the code, let it fix every occurrence, then re-scan. Unsure about a finding? Ask Kavach AI for a second opinion first; answers are drafts from a local model and can be wrong.

Limits per plan are on the pricing page. The live-site audit on the home page complements this scan by checking what an attacker sees from outside.