Tackle WordPress weaknesses and fortify your website Learn more

HTTP cookies are small packets of data stored in your browser. This data may contain sensitive data like passwords or user information and is therefore vulnerable for attacks. To limit vulnerability you can ‘secure’ your cookies by adding specific attributes to the set cookies, making it harder to manipulate by outsiders.

Really Simple SSL uses the HttpOnly, secure and use_only_cookies parameters to make cookies more secure. Since Really Simple SSL helps you in securing your website by switching your site to SSL, we feel like making these changes to the plugin is a simple way in which we can contribute to the overall safety of your website.

Cookies are set by almost every website and are used for a lot of different things, like user tracking, affiliate marketing and authentication. Imagine having your users authentication cookies stolen by malicious actors. That’s something you’d want to avoid at all times and this addition to the free plugin is something which helps in preventing just that.


The HttpOnly flag will tell the browser that this cookie can only be accessed by the server. The main benefit of this is that it prevents cross-site scripting (XSS). For example, this will prevent requests from malicious JavaScript files trying to steal cookies.


The secure parameter will make sure cookies are only sent over a secure SSL connection. This will prevent any cookies being sent over http://, thus securing cookies even more.


the use_only_cookies parameter will tell your website to only store session data in a cookie and not in another way. This prevents attacks involving passing session ids in URLs.


Really Simple SSL will set these parameters in your wp-config.php file. On most WordPress installations this file is writeable and Really Simple SSL will apply the changes automatically. If the file is not writeable, the plugin will show you which code to add so you can add it manually. If you choose to deactivate the plugin, the code will also be removed from the wp-config.php file.

Let us know if you have any questions in regards to this article!

Table of Contents

Peter Tak

Peter Tak

Security Officer at Really Simple Plugins

Read More

Advanced Security

Tackle WordPress weaknesses and fortify your website. New hardening features!


Want to know the in and outs of security jargon? Get to know our features.

Premium support will offer assistance in 24 hours. If you need help, or have any questions just contact our awesome support team/

Related articles