Free
$0
3 deep scans monthly, up to 3 pages each, plus 1 branded managed deployment.
Create accountSet-Cookie response headers and readable browser cookies only.
HttpOnly cookies, cookies set via JavaScript after page load, cookies behind authentication walls, and cookies loaded by third-party
scripts may not be detected. Results are indicative, not exhaustive, and should not be used as a sole basis for compliance decisions.
Enter any website URL to scan for cookies. CFT classifies every cookie by security risk, detects missing Secure, HttpOnly, and SameSite attributes, and generates a defender-ready remediation report.
CFT goes beyond cookie inventory. It analyzes cookie security attributes, assigns severity-based findings, identifies browser-storage exposure, and provides actionable remediation steps for weaknesses involving Secure, HttpOnly, SameSite, third-party tracking, and persistence behavior.
Provide the target website address.
CFT fetches the site and reads all HTTP Set-Cookie response headers automatically.
Each cookie is classified by lifespan, source, security attributes, and type.
Download a standalone HTML report with all findings and remediation steps.
| Cookie Name | Domain | Type & Category | Security Attributes | Findings & Remediation |
|---|
HTTP scans remain free. Create an account for browser-based deep scans, larger crawls, and monthly scan capacity.
$0
3 deep scans monthly, up to 3 pages each, plus 1 branded managed deployment.
Create account$9/month
25 deep scans monthly, up to 10 pages each, plus 1 managed deployment.
Choose Starter$24/month
100 deep scans monthly, up to 25 pages each, plus 5 managed deployments.
Choose Growth$59/month
500 deep scans monthly, up to 50 pages each, plus 25 managed deployments.
Choose AgencyAnnual billing: Starter $90, Growth $240, Agency $590.
A free, open cookie security scanner built for defenders by antibodycyber.com
CFT helps security engineers, privacy auditors, penetration testers, and compliance teams quickly enumerate the cookies a website sets and identify security misconfigurations before attackers do.
Secure attribute β cookie transmittable over HTTPHttpOnly β authentication cookies exposed to XSSSameSite β CSRF riskSameSite=None without Secure β rejected by modern browsersβ‘ HTTP Scan (default) β CFT makes a server-side HTTP GET request to the target URL, follows up to five redirects, and captures all Set-Cookie response headers at each hop. Each cookie is parsed and classified against a security rule set. Fast (~2 s), no browser involved.
π¬ Deep Scan (headless) β CFT launches Chromium, crawls up to 10 same-site pages in one browser context, waits for network activity to settle, and captures cookies plus localStorage and sessionStorage key names. When an βAccept allβ control is present, CFT records storage before and after consent and labels the state. Results include the origin and first page where each key was detected.
Reducing cookie exposure is one layer of protection. These tools address network-level tracking, IP visibility, and credential security.
Threat Protection + no-logs VPN
Blocks tracking cookies and malicious sites at the network level β before they reach your browser. Masks your IP, encrypts traffic, and strips ad trackers from DNS queries.
Get NordVPN →Secure password manager & autofill
Store passwords and passkeys in an end-to-end encrypted vault. A safer alternative to browser-stored credentials that can be exposed through weak session cookies.
Get NordPass →Disclosure: CFT may earn a commission from qualifying purchases through the above links, at no extra cost to you. We only recommend tools that align with this site's privacy and security mission.