Static explanation, not a live CORS test
This page makes no request to the entered URL. It analyzes only metadata kept in this page. Raw URL, origin, and header names or values appear only in explicit local-screen details and are excluded from the report.
Results are conservative. Browser version, redirect chains, caches, proxies, service workers, and server behavior can require review; this tool does not prove success, safety, or full browser-engine parity.
Staged local outcome
Exchange analysis
Request classification
Show explicit local-screen raw details
These raw values are intentionally screen-only. Protect screenshots and shoulder-surfing.
Fixed findings
Fixed remediation checklist
Bounded policy subset
The core compares normalized HTTP(S) origins and effective default ports; classifies GET/HEAD/POST, request-header names, bounded Content-Type values, and credentials modes; and checks supplied CORS response fields. It handles exact and wildcard origin rules, credential conflicts, method/header lists, malformed or duplicate singleton values, Vary, null origin, redirects, and expose-header constraints.
It does not send requests, inspect actual browser state, process cookies or tokens, model every Fetch rule, replay redirects, import HAR, proxy traffic, alter a server, or bypass security.
Optional manual review
CORS exchange review — USD 19
Up to 5 exchanges, one aggregate report, one remediation checklist, and one revision.
Email winni80@gmail.com. In the first email, do not send a URL, origin, cookies, authorization, token, personal data, or raw header values. Send only the value-free report plus browser and server type.
This is an inquiry route only. There is no payment link, and the offer is not evidence of inquiry, demand, payment, or revenue.