Checks

Cookie missing SameSite

A non-session cookie does not set SameSite.

Why it matters

Browsers apply a default, but an explicit Lax or Strict makes the intent obvious.

What to do

Set SameSite=Lax unless the cookie is intentionally cross-site.

Reference

Cookie attributes such as Secure, HttpOnly, and SameSite protect session tokens in browsers.

OWASP Session Management Cheat Sheet