All Security Checks
HeadersLow PriorityPro
Access-Control-Max-Age
This header specifies how long browsers can cache preflight request results.
Why It Matters
Proper caching reduces preflight requests, improving performance. However, overly long cache times can cause issues when CORS policy changes.
How We Check
We verify the max-age value is reasonable (typically 86400 seconds / 24 hours) and consistent across responses.
How to Fix
Set Access-Control-Max-Age: 86400 for daily caching. Adjust based on how frequently your CORS policy changes.
Related Security Checks
Related Tool
CORS Checker
Run all 6 related checks with our free cors checker
Check Your Website Now
Run a free security scan to check for Access-Control-Max-Age issues and 58+ other security vulnerabilities.
Scan Your Website Free