I don’t know but that might be the fact due to this article;
I recomment contacting them directly and asking them to check without their automated api doing it.
Because of this security system, the following things will not work correctly or at all on websites on free hosting.
Access through Android or iOS mobile apps (mobile browsers work fine).
API access to websites (like WordPress XML-RPC).
Access from cURL or other command line clients.
Website code validators and SEO checkers.
Domain ownership verification checks which look at website URLs or HTML code. Some webmasters tools and ad networks do this.
Let's Encrypt and websites providing certificates through Let's Encrypt (like sslforfree.com or zerossl.com).
AJAX requests from other websites (CORS). AJAX requests are only possible on the same (sub)domain.
Hotlinking and embedding images and other (static) files on other websites.