Security Tools

CORS Analyzer

Check whether other websites can read responses from your API. Enter a URL and a test origin that should not be allowed; our server sends a GET with that Origin, a GET with Origin: null and an OPTIONS preflight, and evaluates the CORS response headers. The analyzer flags reflected origins (critical with credentials), allowed null origins, wildcards with credentials, missing Vary: Origin and permissive preflights, and shows every header it received.

  • Encrypted connection
  • No sign-up
  • Free to use

Our server sends three harmless requests: a GET with your test Origin, a GET with Origin: null, and an OPTIONS preflight. No credentials or cookies are sent; only response headers are evaluated.

How to use CORS Analyzer

  1. Enter the API or page URL.
  2. Keep or change the test origin.
  3. Click Analyze CORS.
  4. Fix critical findings first.

CORS Analyzer features

Three requests

GET, null origin and preflight.

Risk rating

Critical, permissive, minor or fine.

Credentials check

The dangerous combination.

Vary: Origin

Cache safety.

Header tables

Exactly what came back.

No credentials sent

Harmless requests only.

When to use CORS Analyzer

  • API security reviews.
  • Debugging CORS errors.
  • Penetration test preparation.
  • Checking CDN or gateway rules.

CORS Analyzer FAQ

When is CORS dangerous?

When the server reflects any origin and allows credentials – then any website can read a logged-in user’s data.

Is Access-Control-Allow-Origin: * a problem?

Not for public data without credentials. It is wrong for user-specific responses.

Why block Origin: null?

Sandboxed iframes and local files send null, so attackers can easily obtain it.

Does CORS protect my API?

No – it only controls browser reads. Always check authentication and authorisation on the server.

CORS is about browsers

CORS relaxes the same-origin policy in browsers. Server-to-server requests ignore it, which is why authorisation must never depend on it.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.

Other useful tools