How to use it
- 1
Enter a public URL.
- 2
Run the cookie policy check.
- 3
Review Set-Cookie count, attributes, and issues.
What the tool can do
- Checks Secure, HttpOnly, and SameSite.
- Flags SameSite=None without Secure.
- Marks persistent cookies by Max-Age/Expires.
Common use cases
- Find cookies missing Secure or HttpOnly.
- Check SameSite policy after release.
- Prepare a baseline for security review.
How it works inside
The tool does not assess legal compliance of cookie banners.
Some cookies may appear only after JavaScript or login flows.
Questions and answers
Is this a legal cookie audit?
No. This is a technical Set-Cookie attribute check, not legal consent assessment.
Why are there no cookies?
The response may not set cookies before login, JavaScript flow, or consent choice.
