Feature docs · Website security · Module: cors-policy
CORS Policy is a Guardbee scan module under website security. Analyzes Access-Control-* headers with at most one harmless Origin reflection probe.
What does it check?
Analyzes Access-Control-* headers with at most one harmless Origin reflection probe. Results appear in the dashboard and scan detail as score, findings, and recommended actions.
Business impact
Overly open CORS hands data to the wrong origins.
Guardbee presents risk, impact, and priority — so product, legal, and engineering share one screen.
How to run it
- Create a Guardbee account (25 credits for new accounts)
- Add a brand / URL
- Select CORS Policy under Website security
- Run the scan; optionally explain findings with BeeAI
Related docs
Frequently asked questions
Is CORS Policy required?
No. Pick modules as needed; you only spend credits on what you run.
Is scanning destructive?
No. Guardbee uses controlled, read-only, limited requests.
Does it work with BeeAI?
Yes. After a scan, BeeAI can summarize findings in business language.