Checks

No Set-Cookie headers

The fetched response did not set any cookies.

Why it matters

There is nothing to grade. Cookies set after login or by JavaScript are not visible here.

What to do

This is informational. Scan a URL that sets the cookie if you want those attributes checked.

Reference

Cookie attributes such as Secure, HttpOnly, and SameSite protect session tokens in browsers.

OWASP Session Management Cheat Sheet