What does a CORS checker test?
A CORS checker tests whether a web server's response headers allow browser code from a specified origin to read a resource. It surfaces Access-Control-Allow-Origin and related preflight behavior, which helps distinguish a browser-enforced cross-origin restriction from an endpoint, authentication, or general network failure.
The controlled request is sent through a server endpoint protected by the shared SSRF guard so public targets can be inspected safely. A successful result applies only to the tested origin, method, and requested headers; it does not grant every site access, and command-line clients such as curl do not enforce CORS at all.