Feature docs · Website security · Module: cors-policy
CORS Policy is a Guardbee scan module under website security. Analyzes Access-Control-* headers with at most one harmless Origin reflection probe.
What does it check?
Analyzes Access-Control-* headers with at most one harmless Origin reflection probe. Results appear in the dashboard and scan detail as score, findings, and recommended actions.
Business impact
Overly open CORS hands data to the wrong origins.
Guardbee presents risk, impact, and priority — so product, legal, and engineering share one screen.
How to run it
- Create a Guardbee account (14-day free trial)
- Add a brand / URL
- Select CORS Policy under Website security
- Run the scan; optionally explain findings with BeeAI
Related docs
Run this module now
Use CORS Policy with no scan quota. Start with a 14-day free trial.
Frequently asked questions
Is CORS Policy required?
No. Pick modules as needed; there is no scan quota — limits are active brands.
Is scanning destructive?
No. Guardbee uses controlled, read-only, limited requests.
Does it work with BeeAI?
Yes. After a scan, BeeAI can summarize findings in business language.