Skip to main content
New: 190 SEO checks now available. See what's new
mediumSecurityCOOKIE_WITHOUT_HTTPONLY

Cookie missing HttpOnly flag — the fix

One or more cookies are set without the HttpOnly flag, making them accessible to JavaScript via document.cookie.

Where this fits: security in SEO

Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.

Why cookie missing httponly flag hurts your rankings

Cookies without HttpOnly can be stolen through XSS (Cross-Site Scripting) attacks. If an attacker injects malicious JavaScript, they can read all non-HttpOnly cookies and exfiltrate session tokens or other sensitive data.

This is a medium-severity issue: individually modest, but it compounds — dozens of medium issues across hundreds of pages add up to a real quality deficit in how search engines assess the site.

How to fix it

Add the HttpOnly attribute to all cookies that do not need to be accessed by client-side JavaScript. Session cookies should always have HttpOnly set.

Set-Cookie: sessionId=abc123; Secure; HttpOnly; SameSite=Strict

Security best practices

  • Serve everything over HTTPS and redirect HTTP with a single 301.
  • Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
  • Eliminate mixed content — one insecure asset breaks the padlock.
  • Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
  • Monitor Search Console's security section — Google often knows you're hacked before you do.

The full library: SEO best practices, by category.

Frequently asked questions

What does "Cookie missing HttpOnly flag" mean?

One or more cookies are set without the HttpOnly flag, making them accessible to JavaScript via document.cookie.

Why does cookie missing httponly flag matter for SEO?

Cookies without HttpOnly can be stolen through XSS (Cross-Site Scripting) attacks. If an attacker injects malicious JavaScript, they can read all non-HttpOnly cookies and exfiltrate session tokens or other sensitive data.

How do I fix cookie missing httponly flag?

Add the HttpOnly attribute to all cookies that do not need to be accessed by client-side JavaScript. Session cookies should always have HttpOnly set.

How serious is this issue?

This is a medium-severity issue: individually modest, but it compounds — dozens of medium issues across hundreds of pages add up to a real quality deficit in how search engines assess the site. It belongs to the security family of checks.

How do I find every page affected by this on my site?

Run a free Dr Urls audit: it crawls your site, detects cookie missing httponly flag on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.

Does your site have this issue?

A free Dr Urls audit crawls your site, finds every page affected by cookie missing httponly flag, and hands you a ready-made fix task.

Check my site free

Related security guides