How to use it
- 1
Enter a public resource URL.
- 2
Enter the Origin to test.
- 3
Review ACAO, credentials, and cache variation.
What the tool can do
- Sends a safe request with an Origin header.
- Checks wildcard + credentials misconfiguration.
- Flags Vary: Origin for cache correctness.
Common use cases
- Check whether a specific frontend Origin is allowed.
- Find dangerous wildcard with credentials.
- Prepare an API for safe CDN/cache behavior.
How it works inside
The check is not full browser CORS emulation.
The result is based on one safe HTTP request with the given Origin.
Questions and answers
Why is * + credentials bad?
That combination is not a controlled access policy and must not be used for credentialed access.
Does this check OPTIONS preflight?
No. A preflight matrix is a later extension to avoid mixing simple header checks with heavier API testing.
