Title: HttpOnly flag not set
Last modified: February 24, 2022

---

# HttpOnly flag not set

 *  Resolved [Josh Bedford](https://wordpress.org/support/users/joshbedford/)
 * (@joshbedford)
 * [4 years, 3 months ago](https://wordpress.org/support/topic/httponly-flag-not-set/)
 * Hi there,
 * I’ve noticed the cookie set for anti-bot is lacking an HttpOnly flag. Could you
   confirm whether this is intentional or something that is to be corrected in an
   upcoming update? I guess it may be intentional due to the way the JS presumably
   needs to be read for anti-bot to function, but just looking for confirmation 
   please so we can allay any worries from clients.
 * Thanks

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Author [gioni](https://wordpress.org/support/users/gioni/)
 * (@gioni)
 * [4 years, 3 months ago](https://wordpress.org/support/topic/httponly-flag-not-set/#post-15399883)
 * Hi!
 * Your assumptions are correct. Setting those cookies without the HttpOnly flag
   is quite normal because 1) the cookies hold random values not linked to a user
   and 2) are not used for authenticating users. No corrections are needed.
 *  Thread Starter [Josh Bedford](https://wordpress.org/support/users/joshbedford/)
 * (@joshbedford)
 * [4 years, 3 months ago](https://wordpress.org/support/topic/httponly-flag-not-set/#post-15399891)
 * Hi [@gioni](https://wordpress.org/support/users/gioni/), that’s great – thanks
   for confirming!

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘HttpOnly flag not set’ is closed to new replies.

 * ![](https://s.w.org/plugins/geopattern-icon/wp-cerber_77a9bf.svg)
 * [WP Cerber Security, Anti-spam & Malware Scan](https://wordpress.org/plugins/wp-cerber/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wp-cerber/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wp-cerber/)
 * [Active Topics](https://wordpress.org/support/plugin/wp-cerber/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wp-cerber/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wp-cerber/reviews/)

## Tags

 * [cookie](https://wordpress.org/support/topic-tag/cookie/)

 * 2 replies
 * 2 participants
 * Last reply from: [Josh Bedford](https://wordpress.org/support/users/joshbedford/)
 * Last activity: [4 years, 3 months ago](https://wordpress.org/support/topic/httponly-flag-not-set/#post-15399891)
 * Status: resolved