Skip to content

HTTP security

Cookie security checker

See the cookies a site's home page sets over HTTPS and whether each carries the attributes that keep it off plain HTTP, out of reach of scripts and out of requests that start on other sites.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

A cookie's attributes decide where the browser sends it and who can read it. Secure keeps it to HTTPS connections. HttpOnly hides it from JavaScript, so a script injected into the page cannot read it. SameSite controls whether it travels with requests that start on another site: Strict never, Lax only when the visitor follows a link to the site, None always, and then it must also be Secure.

Session and sign-in cookies matter most, because whoever holds one is, to the site, the signed-in user. The check recognises them by name, so a session cookie with an unusual name is judged like any other cookie, and a harmless one with token in its name may be flagged.

A pass means the home page set no cookies, or every cookie had Secure and SameSite and every session-like cookie had HttpOnly. Many sites set no cookies on the home page at all; that is a genuine pass, not a sign the check did not look.

How to fix common issues

Cookie set without the Secure flag

Add the Secure attribute to every cookie the site sets over HTTPS.

More in the Cookie security check reference

Session cookie readable by scripts

Add the HttpOnly attribute to session and authentication cookies.

More in the Cookie security check reference

Cookie set without SameSite

Add SameSite=Lax (or Strict where possible) to cookies.

More in the Cookie security check reference

Scope and limitations

Related guides

Questions

What is the difference between Secure and HttpOnly?
Secure stops the browser sending the cookie over plain HTTP. HttpOnly stops JavaScript on the page reading it. A session cookie should have both.
Which SameSite value should I use?
Lax suits most cookies, including sessions on sites people reach by following links. Strict is tighter but leaves the cookie out when a visitor arrives from another site. None is only for cookies that must work inside other sites, and requires Secure.
Why does the checker show no cookies for my site?
The home page did not set any. Many sites set cookies only after sign-in, or on the application's own host, which this check does not visit.

Related security tools