Audit cookie flags, session management, and token security for your application.
Overview
Cookies are the primary mechanism for maintaining user sessions. Insecure cookie configuration can lead to session hijacking, cross-site attacks, and data leakage. Our scanner checks all cookies set by your application for proper security flags and session management best practices.
What this scanner does
Analyzes all cookies set by your application for Secure, HttpOnly, SameSite flags, path restrictions, and expiration settings. Checks session token entropy, identifies overly permissive cookie scopes, and tests for session fixation vectors.
Why it matters
Insecure cookies are a direct path to session hijacking. Without the HttpOnly flag, JavaScript can steal session tokens via XSS. Without the Secure flag, cookies transmit over unencrypted connections. Without SameSite, cookies are vulnerable to CSRF attacks.
Common findings
OWASP Top 10 coverage
Get a full report with AI-ready fix prompts in 30 seconds. No setup required.
Related checks
Vulnerability Detection
Check if your forms and API endpoints are protected against cross-site request forgery.
Vulnerability Detection
Test your login, signup, and password reset flows for common security weaknesses.
Configuration Audit
Check if your site has the right HTTP security headers to prevent common attacks.
Compliance Check
Check for privacy policy, cookie consent, terms of service, and GDPR compliance indicators.
Configuration Audit
Audit your Supabase project for RLS misconfigurations, exposed APIs, and insecure auth settings.
Configuration Audit
Probe your Firebase Realtime Database and client config from outside, with nothing to connect.