HTTP response header

The Timing-Allow-Origin response header specifies origins that are allowed to see values of attributes retrieved via features of the Resource Timing API which would otherwise be reported as zero due to cross-origin restrictions

Header usage statistics

Timing-Allow-Origin response header information and usage statistics.

Websites using header Timing-Allow-Origin 63,711
Percentage of websites that use Timing-Allow-Origin header 0.12%
Total discovered header values 112
Header uses directives Yes
Header values are unique or random No
Most popular in the country United States of America

Timing-Allow-Origin Directives (1 total)

  • *

Timing-Allow-Origin Directives

Timing-Allow-Origin directives value information and usage statistics

Directive Share Websites count Unique Values
* % 14,583 1

Distribution by websites popularity

Timing-Allow-Origin detection in the top websites by popularity

Top 10k sites 151 websites
Top 100k sites 275 websites
Top 1m sites 1,170 websites

Websites utilizing Timing-Allow-Origin

List of websites that use Timing-Allow-Origin header

Domain Country Rank Contacts
maps.google.com United States of America 15
lh3.googleusercontent.com United States of America 39
1.bp.blogspot.com United States of America 48
maxcdn.bootstrapcdn.com United States of America 77
tripadvisor.com United States of America 114
www.tripadvisor.com United States of America 114
See full domain list
Flat price per the report, subscription is not required.

Geographical Distribution

Header usage distribution by websites across the globe.

Common header values

List of top common Timing-Allow-Origin header values

Header value Value prevalence
* 98.66%
https://www.google.com 0.28%
*, * 0.28%
https://www.tripadvisor.com 0.21%
https://ads.google.com 0.09%
https://www.bbc.co.uk, https://www.bbc.com 0.08%
https://twitter.com, https://mobile.twitter.com 0.05%
https://allegro.pl, http://allegro.pl 0.03%
same-origin 0.02%
https://sentry.degrasboom.nl, https://stats.degrasboom.nl 0.02%
https://github.com 0.02%
true 0.01%
Timing-Allow-Origin: https://parrotsec.org,https://*.parrotsec.org,https://parrot.sh,https://*.parrot.sh,https://*.cdn.parrot.sh,https://*.d.cdn.parrot.sh,https://*.l.cdn.parrot.sh,https://*.any.parrot.sh,https://*.gibson.infra.parrot.sh,https://.*parrotl 0.01%
https://allegro.pl 0.01%
https://badoo.com 0.01%
https://www.gog.com, https://www.gogalaxy.com, https://embed.gog.com 0.01%
https://www.cdw.com,https://www.cdwg.com,https://www.cdw.ca 0.01%
none 0.01%
https://log.tokopedia.net 0.01%
https://www.opentable.com 0.01%