Security

Cookie Security Analyzer

A new tool extracted from the codebase.

Last reviewed by the Radiatus Cloud team

Cookie Security Analyzer

Analyze HTTP cookies for missing Secure, HttpOnly, and SameSite attributes

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Check your cookies for the right flags

A cookie is only as safe as its flags, and missing ones expose sessions to theft and misuse. This analyser checks cookies for the security attributes that matter, Secure, HttpOnly, SameSite, so you can confirm your own cookies are set safely.

What the flags protect against

Each cookie flag closes a specific hole. Secure stops the cookie being sent over unencrypted HTTP where it could be intercepted. HttpOnly stops scripts reading it, which defends the session against cross-site scripting theft. SameSite limits when the cookie is sent cross-site, defending against cross-site request forgery. A session cookie missing these is a common and serious weakness, because the session token it carries is exactly what an attacker wants. Checking the flags confirms your cookies are hardened.

Harden your sessions

The tool runs entirely in your browser, so nothing you paste is uploaded, which is exactly what you want when the input is your own security-sensitive data.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

What do the Secure, HttpOnly and SameSite flags do?

Secure sends the cookie only over HTTPS; HttpOnly hides it from scripts, defending against theft via cross-site scripting; SameSite limits cross-site sending, defending against request forgery.

Why does a session cookie need these?

Because it carries the session token an attacker wants. Missing flags let the token be intercepted, stolen by a script, or misused cross-site.

Which flag defends against XSS session theft?

HttpOnly, which stops JavaScript reading the cookie, so a cross-site scripting flaw cannot steal the session token directly.

What does the analyser check?

Whether your cookies set the Secure, HttpOnly and SameSite attributes appropriately, flagging any that are missing or weak.

Are my cookies uploaded?

No. The analysis runs entirely in your browser.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started β€” no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.