Website Cookie Checker
See which cookies a page sets and whether they are configured safely. The checker reads the Set-Cookie headers of the page response and lists each cookie’s name, flags – Secure, HttpOnly, SameSite, Partitioned – lifetime and domain, guesses its purpose from common names such as _ga or PHPSESSID, and flags problems: missing Secure on https, session cookies without HttpOnly, missing SameSite, SameSite=None without Secure, lifetimes over 400 days, broken __Host- prefixes and very large cookies. Cookie values are never shown or stored.
- Encrypted connection
- No sign-up
- Free to use
How to use Website Cookie Checker
- Enter the page address.
- Click “Check cookies”.
- Review the flags and findings.
- Fix the cookie settings in your application.
Website Cookie Checker features
Security flags
Secure, HttpOnly, SameSite.
Lifetime
Session or duration.
Purpose hints
Analytics, marketing, necessary.
Prefix rules
__Host- and __Secure-.
Privacy
Values never returned.
Safe fetching
Public addresses only, with size and time limits.
When to use Website Cookie Checker
- Security reviews.
- GDPR and cookie banner checks.
- Debugging login problems.
- Checking framework defaults.
Website Cookie Checker FAQ
Why are some cookies missing?
Cookies set by JavaScript (analytics, consent tools) after the page loads are not in the HTTP response. Check them in your browser’s developer tools.
What does SameSite do?
It controls whether a cookie is sent with requests from other sites, protecting against cross-site request forgery.
Why limit lifetime to 400 days?
Chrome caps cookie lifetimes at 400 days; longer values are shortened.
Do I need consent for these cookies?
Strictly necessary cookies usually not; analytics and marketing cookies usually yes under GDPR/ePrivacy. This is not legal advice.
Cookies done right
Session cookies should be Secure, HttpOnly and SameSite=Lax or Strict. These three flags block the most common cookie theft and forgery attacks.
Keep cookies small and few; every cookie is sent with every request to its domain.
How it works: our server downloads the page once through a guarded fetcher that only connects to public addresses, follows a limited number of redirects and stops after a size and time limit. The HTML is then analysed in your browser as inert text – scripts on the page never run and nothing is stored.
What it cannot see: content and resources that a page adds with JavaScript after it loads, pages behind a login, and servers that block automated requests. For those, open the page in your browser, use its developer tools, or paste the page source where the tool offers a paste option.
Use the results as a starting point: fix the items marked red first, review the yellow warnings in context, and run the check again after a change. Requests are rate-limited to keep the service fair; if you check many pages in a row, wait a few minutes.
Related checks on this site cover the rest of a technical review – speed and Core Web Vitals, security headers, structured data, accessibility and SEO signals – so you can work through a whole site audit one topic at a time.
Who it is for: site owners checking their own pages, developers debugging a release, SEO and marketing teams auditing clients or competitors, and students learning how the web works. No account or installation is needed, and the results are plain text and tables you can copy into a report or ticket.