CORS Checker For Your API
Send a request from an origin your site has never heard of and see whether it is trusted anyway.
Free, no account. Passive checks only — the same requests a browser or DNS lookup makes.
What This Checks
- Whether the response reflects an arbitrary Origin in Access-Control-Allow-Origin
- Whether credentials are allowed alongside it
- Wildcard policies and the 'null' origin
Why It Matters
A CORS policy that trusts every origin — especially with credentials — lets any website a signed-in user visits read their data from your API.
AI-generated backends often ship with a permissive policy copied from a tutorial so the frontend 'just works'. Check the URL of an API endpoint, not only your homepage.
Check Every Deploy, Not Just Today
Every ZipLoom deploy runs a dependency vulnerability audit and a live check of your headers, TLS and DNS — and ZipLoom can scan your source code on demand or on every commit.
Scan Your App FreeMore Free Checks
Security Headers Check · Email Security Check For Any Domain · Is Your Source Code Public? Source Map Check