Test HTTPOnly and Secure flag in Cookie response headers.
Your website sends cookies to the browser. Good! But are they secure?
A simple implementation like injecting HTTPOnly and Secure in Set-Cookie header can prevent web vulnerabilities such as cross-site scripting (XSS).
Domsignal Secure Cookie Test checks the HTTP response headers for Set-Cookie.
Make sure your website is in top shape with Domsignal - explore the suite of performance, SEO and security metrics testing tools now!