← All Tools
Cookie Security Analyzer
Parse Set-Cookie headers and flag missing Secure / HttpOnly / SameSite, weak prefixes, and broad scopes.
🔒 100% client-side. Cookie values are never echoed by default — you can reveal per cookie.
Pair with the HTTP Security Headers Grader and the CSP Builder.