Breaking Same Origin Policy (for the alexa top 1m)
ejj.io
ejj.io
This is false (unless `Access-Control-Allow-Credentials` is set). See CORS 101: https://annevankesteren.nl/2012/12/cors-101
It's safe to put Access-Control-Allow-Origin:* on any publicly-accessible server, since another server could simply proxy that stuff anyway.