What it checks
The attributes on cookies the site sets over HTTPS: Secure on every cookie, HttpOnly on cookies that look like sessions, and SameSite.
A pass means: Cookies set by the site carry the expected security attributes.
Possible findings
Cookie set without the Secure flag
Severity: MediumConfidence: High confidenceKind: Security issue
What we found
A cookie was set over HTTPS without the Secure attribute.
Why it matters
Without Secure, the browser will also send the cookie over plain HTTP, where it can be intercepted. This matters most for session and authentication cookies.
How to fix it
Add the Secure attribute to every cookie the site sets over HTTPS.
Session cookie readable by scripts
Severity: LowConfidence: Medium confidenceKind: Recommended hardening
What we found
A cookie that looks like a session or authentication cookie was set without the HttpOnly attribute.
Why it matters
Without HttpOnly, any script on the page can read the cookie, so a cross-site scripting bug could steal sessions. Some cookies legitimately need to be readable by scripts, so check this one.
How to fix it
Add the HttpOnly attribute to session and authentication cookies.
Cookie set without SameSite
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
A cookie was set without a SameSite attribute.
Why it matters
Browsers now default to SameSite=Lax, which protects most cases. Setting it explicitly documents intent and protects users on older browsers against cross-site request forgery.
How to fix it
Add SameSite=Lax (or Strict where possible) to cookies.

