Cookie without HttpOnly
-
Hello,
I am using the Sucuri Security Plugin for a client at https://www.tomblubaugh.net using Striking Multiflex as the theme and it is a great tool with great instructions on securing and hardening a wordpress website, thank you.I have one warning listed during the malware scan that I cannot seem to get rid of.
Cookie without HttpOnly
We identified a Cookie on your site that was not set as HttpOnly.
https://kb.sucuri.net/warnings/hardening/cookies-httponlyThe link says to use ‘Set-Cookie: COOKIE=VAL; path=/; domain=.domain.com; secure; HttpOnly’ to set your cookies; however, it does not explain where to put this code and neither does the two sub-links explaining this process.
I have researched other ways to set cookies but none seem to remove this warning from the plugin.
Where should this code be placed and/or Is it possible to determine which cookie is causing this warning?
Thank you for all your help,
Shawn
- The topic ‘Cookie without HttpOnly’ is closed to new replies.