Want a weekly re-check of this?
Drop your email — we will re-run this check every 7 days and write to you only if the result comes back worse than the one before it. Free.
One-click unsubscribe in every email. We never share email addresses. By subscribing you agree to our privacy policy.
What is Cookie Security Analysis?
Cookie security analysis checks whether your website sets cookies with proper security flags: HttpOnly (prevents JavaScript access), Secure (HTTPS-only transmission), and SameSite (CSRF protection). Missing flags expose users to session hijacking, CSRF attacks, and cross-site tracking. This tool scans all Set-Cookie headers and grades each cookie individually.
Learn more
Frequently Asked Questions
Which cookie flags are mandatory in 2026?
HttpOnly (JavaScript-inaccessible, prevents XSS theft), Secure (HTTPS-only), SameSite=Lax or Strict (CSRF protection), proper Expires/Max-Age. For auth cookies use __Host- or __Secure- prefix. The tool audits all cookies and flags unsafe ones.
Related guides
Longer-form reading on this topic from the knowledge base.
Automate this check
Set up continuous monitoring and get an alert when something breaks. No manual runs to remember.