Checks

No CORS headers exposed

The main response did not include Access-Control-Allow-Origin.

Why it matters

Browsers will not let another website read this response. That is the right default for a normal page.

What to do

No change is required unless this URL is an API that a browser app on another origin must read.

Reference

CORS controls which origins may read responses and must not expose credentialed data broadly.

MDN — Cross-Origin Resource Sharing (CORS)