No Cross-Origin-Embedder-Policy is set
What this check looks for
The page has not required embedded resources to opt in to being loaded. This is optional and only matters for specific advanced features.
Why it matters
Nothing is wrong. Setting this is how a page becomes cross-origin isolated, which some measurement and multithreading APIs require — and it is disruptive to enable, because every third-party resource must then opt in.
When the check passes, your report says: “A Cross-Origin-Embedder-Policy makes embedded resources opt in”.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- Web security
- Module
- Web security headers
- Fix owned by
- user
- In the ruleset since
- 2026.09
Technical detail
‹value›
require-corp makes every cross-origin subresource carry Cross-Origin-Resource-Policy or CORS headers, or fail to load. credentialless is the gentler variant that loads them without credentials. Enable it only when you need cross-origin isolation, and audit every third-party resource first.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.
Other web security headers checks
- No Cross-Origin-Opener-Policy is set
- No Cross-Origin-Resource-Policy is set
- No Content Security Policy is enforced
- The policy leaves plugins or the base URL unrestricted
- The Content Security Policy is report-only
- The policy allows eval()
- The policy allows inline scripts or styles
- The policy allows resources from anywhere
- A security header was sent twice with different values
- HSTS max-age is shorter than six months
- HTTP Strict Transport Security is not in force
- HSTS does not cover subdomains