SameSite Cookies Security & Risk Analysis

wordpress.org/plugins/samesite

CSRF-protection for authentication cookies. When enabled, this plugin makes sure the "SameSite" flag is set in authentication cookies.

900 active installs v2.1 PHP 7.0+ WP 6.2+ Updated Jul 23, 2023
cookiescsrfsamesitesecurity
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SameSite Cookies Safe to Use in 2026?

Generally Safe

Score 85/100

SameSite Cookies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'samesite' plugin v2.1 demonstrates a strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, SQL queries without prepared statements, and properly escaped output indicates a diligent approach to secure coding practices. Furthermore, the lack of file operations, external HTTP requests, and the absence of any listed vulnerabilities in its history are all positive indicators of a well-maintained and secure plugin. The plugin has a minimal attack surface with no identifiable entry points requiring further security scrutiny.

While the static analysis reveals no immediate code-level vulnerabilities, the complete lack of nonce and capability checks across all identified entry points (even though there are none) is a notable observation. While not a current risk given the zero entry points, it suggests a potential area for future improvement if the plugin's functionality expands. The vulnerability history being entirely clean is an excellent sign, suggesting a history of secure development and prompt patching if any issues have ever arisen.

In conclusion, 'samesite' v2.1 appears to be a highly secure plugin. Its strengths lie in its clean code, absence of common vulnerabilities, and a completely transparent vulnerability history. The only minor point of consideration is the lack of implemented authentication checks, which is more of a prophylactic suggestion for future development rather than an immediate risk given its current limited attack surface.

Vulnerabilities
None known

SameSite Cookies Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SameSite Cookies Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

SameSite Cookies Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

SameSite Cookies Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedJul 23, 2023
PHP min version7.0
Downloads23K

Community Trust

Rating50/100
Number of ratings11
Active installs900
Developer Profile

SameSite Cookies Developer Profile

Ayesh Karunaratne

7 plugins · 8K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SameSite Cookies

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

JS Globals
WP_SAMESITE_COOKIE
FAQ

Frequently Asked Questions about SameSite Cookies