30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.3.01 | Detect wildcard Access-Control-Allow-Origin: * on sensitive routes | None |
| 7.3.02 | Validate only trusted origins are allowed | Strict whitelist |
| 7.3.03 | Validate origin reflection is not enabled (echo origin) | Disabled |
| 7.3.04 | Detect CORS misconfig on API endpoints returning private data | None |
| 7.3.05 | Validate HTTPS-only origins enforced | Enforced |
| 7.3.06 | Detect preflight responses allowing unknown origins | None |
| 7.3.07 | Validate CORS headers not injected by plugins/themes | Clean |
| 7.3.08 | Detect multiple conflicting CORS policies | None |
| 7.3.09 | Validate API gateway enforces correct origin checks | Enforced |
| 7.3.10 | Compute Origin Validation Integrity Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.3.11 | Validate allowed methods restricted to minimal required | Restricted |
| 7.3.12 | Detect unsafe PUT, DELETE, PATCH exposure | None |
| 7.3.13 | Validate sensitive endpoints require auth despite CORS allowance | Required |
| 7.3.14 | Validate Access-Control-Allow-Headers not overly permissive | Minimal |
| 7.3.15 | Detect custom headers exposing internal metadata | None |
| 7.3.16 | Validate preflight caching reasonable (no excessive max-age) | Reasonable |
| 7.3.17 | Detect exposure of CORS methods unused by app | None |
| 7.3.18 | Validate no bypass via alternative endpoints | None |
| 7.3.19 | Detect OPTIONS requests returning sensitive data | None |
| 7.3.20 | Compute Access-Control Permission Tightness Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.3.21 | Validate CORS does not expose cookies where not required | Not exposed |
| 7.3.22 | Validate Access-Control-Allow-Credentials enabled only when safe | True only on private endpoints |
| 7.3.23 | Detect token leakage through permissive CORS | None |
| 7.3.24 | Validate session cookies marked SameSite correctly | Strict/Lax |
| 7.3.25 | Detect credentialed requests allowed from untrusted origins | None |
| 7.3.26 | Validate API responses not exposing internal IDs | Protected |
| 7.3.27 | Detect abuse of open CORS for scraping | None |
| 7.3.28 | Validate OAuth flows enforce strict redirect origin rules | Strict |
| 7.3.29 | Detect misconfigured proxies adding unsafe CORS headers | None |
| 7.3.30 | Compute CORS Exposure & Data-Leak Risk Score | Finalized |
← 7.2 Mixed Content Checks7.4 Cookie Consent, GDPR & Privacy Metadata →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).