Home / Check catalog / 7. Security & Privacy / 7.3 CORS & Access-Control Exposure

7.3 CORS & Access-Control Exposure

30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.

Origin Validation — Strictness, Whitelisting & Policy Safety

IDCheckPasses whenWeightRuns
7.3.01Detect wildcard Access-Control-Allow-Origin: * on sensitive routesNoneCriticalDeterministic
7.3.02Validate only trusted origins are allowedStrict whitelistCriticalDeterministic
7.3.03Validate origin reflection is not enabled (echo origin)DisabledHeavyDeterministic
7.3.04Detect CORS misconfig on API endpoints returning private dataNoneHeavyDeterministic
7.3.05Validate HTTPS-only origins enforcedEnforcedHeavyDeterministic
7.3.06Detect preflight responses allowing unknown originsNoneMediumDeterministic
7.3.07Validate CORS headers not injected by plugins/themesCleanMediumDeterministic
7.3.08Detect multiple conflicting CORS policiesNoneMediumDeterministic
7.3.09Validate API gateway enforces correct origin checksEnforcedMediumDeterministic
7.3.10Compute Origin Validation Integrity ScoreFinalizedCriticalDeterministic

Access-Control Requests — Methods, Headers & Permission Scope

IDCheckPasses whenWeightRuns
7.3.11Validate allowed methods restricted to minimal requiredRestrictedHeavyDeterministic
7.3.12Detect unsafe PUT, DELETE, PATCH exposureNoneHeavyDeterministic
7.3.13Validate sensitive endpoints require auth despite CORS allowanceRequiredHeavyDeterministic
7.3.14Validate Access-Control-Allow-Headers not overly permissiveMinimalMediumDeterministic
7.3.15Detect custom headers exposing internal metadataNoneMediumDeterministic
7.3.16Validate preflight caching reasonable (no excessive max-age)ReasonableMediumDeterministic
7.3.17Detect exposure of CORS methods unused by appNoneMediumDeterministic
7.3.18Validate no bypass via alternative endpointsNoneMediumDeterministic
7.3.19Detect OPTIONS requests returning sensitive dataNoneMediumDeterministic
7.3.20Compute Access-Control Permission Tightness ScoreFinalizedCriticalDeterministic

Security & Data-Leak Protection — Cookies, Tokens, Auth Flows

IDCheckPasses whenWeightRuns
7.3.21Validate CORS does not expose cookies where not requiredNot exposedHeavyDeterministic
7.3.22Validate Access-Control-Allow-Credentials enabled only when safeTrue only on private endpointsHeavyDeterministic
7.3.23Detect token leakage through permissive CORSNoneHeavyDeterministic
7.3.24Validate session cookies marked SameSite correctlyStrict/LaxMediumDeterministic
7.3.25Detect credentialed requests allowed from untrusted originsNoneMediumDeterministic
7.3.26Validate API responses not exposing internal IDsProtectedMediumDeterministic
7.3.27Detect abuse of open CORS for scrapingNoneMediumDeterministic
7.3.28Validate OAuth flows enforce strict redirect origin rulesStrictMediumDeterministic
7.3.29Detect misconfigured proxies adding unsafe CORS headersNoneMediumDeterministic
7.3.30Compute CORS Exposure & Data-Leak Risk ScoreFinalizedCriticalDeterministic

← 7.2 Mixed Content Checks7.4 Cookie Consent, GDPR & Privacy Metadata →

Run these checks on your site

A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.

See plans

Machine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).