SameSite Cookies
by Ayesh Karunaratne 2.5 (11 reviews)

SameSite Cookies

CSRF-protection for authentication cookies. When enabled, this plugin makes sure the "SameSite" flag is set in authentication cookies.

SameSite Cookies ranks #7,734 among WordPress.org plugins with 700+ active installations, is #497 of 4,499 in the Security category, a 2.5/5 rating from 11 reviews, and was last updated Jul 23, 2023. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 6.3.10 (Current: 7.1)
v2.1 Current Version v2.1
Updated 3 years ago Last Update on 23 Jul, 2023
Refreshed 7 hours ago Last Refreshed on
#497 of 4,499 in Security Top 25% by installs No update in over a year
View on WordPress.org
Rank
#7,734
-3 this week
Active Installs
700+
-11.9%
KW Avg Position
36
No change
Downloads
24.8K
+13 today
Support Resolved
0%
No change
Rating
50%
Review 2.5 out of 5
2.5 (11 reviews)

Next Milestone 800

Total Progress 92%
700+ 800+
56
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 8 more installs to reach 800+

Rank Changes

7,732 7,737 7,743 7,748 7,753 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
7,711 7,725 7,739 7,752 7,766 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #7,734
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 10 20 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

2.5
11 reviews
Overall 50%
5
4 (36%)
4
0 (0%)
3
0 (0%)
2
1 (9%)
1
6 (55%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for SameSite Cookies. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site administrators concerned about cross-site request forgery protection on authentication cookies. It adds the SameSite cookie flag to WordPress authentication cookies, with a built-in workaround so it works even on PHP versions older than 7.3.

  • Adds SameSite flag to auth cookies
  • Prevents Cross-Site Request Forgery attacks
  • Works on PHP versions before 7.3
  • No administrative UI needed
  • Configurable via wp-config.php
  • Choose Lax, Strict, or None

Frequently Asked Questions

Common questions about SameSite Cookies

Yeah, probably. This plugin uses what's called "pluggable functions" supported in WordPress to replace wp_set_auth_cookie function. This means that any other plugin that tampers with the login cookie parameters will override this plugin, and this plugin may not even get a chance to do what it does.
Go to the Login page of your WordPress site, and open your browser's development tools. Inspect the HTTP POST request made by the browser when you submit the login form. The response headers for Setcookie response headers must contain Samesite=Lax (or the configured value) if the plugin is working. Note that cookies apart from the authentication cookies are not handled by this plugin, nor it makes sense to add SameSite attribute to them. See the screenshot as well.
No. PHP 7.3 officially added SameSite cookie support, but this plugin comes with a polyfill to extend support to all previous PHP versions.
Without SameSite cookie, WordPress core and third party plugins must implement their own CSRF checks, which can be overlooked, intentionally ignored, or sometimes not even have thought about, which can be the case for contributed plugin. This plugin attempts to solve this with different take and complement existing solutions.

Sign In / Register

You need to sign in or register to use this feature.