What the checker shows
For every Set-Cookie header in the response: name, domain, expiry (session or a date), and whether Secure, HttpOnly and SameSite are set. Each cookie gets a verdict.
Recommended settings
- Secure on every cookie of an HTTPS site.
- HttpOnly on session and login cookies, so injected scripts cannot steal them.
- SameSite=Lax for most cookies (protects against CSRF); SameSite=None; Secure only for cookies that must work across sites.
- Short expiry times for authentication cookies.
Limits of this check
The checker sees cookies set by the server when the page first loads. Analytics, advertising and consent tools usually set cookies with JavaScript after the page loads; those need a browser-based scan for a full cookie audit.
Frequently asked questions
Why does SameSite=None need Secure?
Browsers reject SameSite=None cookies that are not also marked Secure.
Is a session cookie safe?
A session cookie is deleted when the browser closes. It is safe when it is Secure, HttpOnly and has a SameSite value.
Does this check cover GDPR compliance?
No. It checks technical cookie flags. GDPR compliance also requires consent for non-essential cookies, which needs a full browser scan.

