Discover 160+ free tools for web scraping, SEO analysis, OSINT, and more. 30 free uses every day — no signup required.
CORS Misconfiguration Checker tests a website's Cross-Origin Resource Sharing configuration by sending requests with various Origin headers and checking for vulnerable configurations.
If CORS reflects any origin or allows credentials with wildcard, attackers can read sensitive data from another site using the victim's cookies.
Keep exploring
Looking for more in Security? Try Email Security, Mixed or CSP — or browse the full Security collection .
You might also like
Check DMARC, SPF, and DKIM DNS records for any domain to assess email authentication and prevent spoofing.
Find HTTP resources loaded on HTTPS pages. Detect active and passive mixed content issues.
Analyze Content Security Policy headers. Check for unsafe-inline, unsafe-eval, and wildcards.
Analyze cookies set by a website. Check Secure, HttpOnly, SameSite flags and compliance issues.
Analyze website loading speed, resource counts, render-blocking scripts, and get optimization recommendations.
Test regular expressions against text with match highlighting, groups, and flags support.
Looking for something specific? Browse all 158 Krawly tools