PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Csrf
  4. SameSite Cookies
SameSite Cookies icon

SameSite Cookies

CSRF-protection for authentication cookies. When enabled, this plugin makes sure the "SameSite" flag is set in authentication cookies.

By Ayesh Karunaratne·Csrf·Free
2.5(11 reviews)
·900 active installs·Updated 2 years ago
DownloadVisit HomepageCompare

As of April 2026, SameSite Cookies is a WordPress csrf plugin with 900 active installations and a 2.5/5 rating from 11 reviews. It has been downloaded 23K+ times in total. Requires WordPress 6.2+ and PHP 7.0+. Available on WordPress.org since 2019. Last updated 2 years ago — may have compatibility concerns. Top alternative: Comment Form CSRF Protection.

2.5/511 reviews
900active installs
23K+total downloads
7 yearssince 2019

Overview

This plugin adds the “SameSite” cookie flag to WordPress’s authentication cookies. On supported browsers (all current IE, Edge, Chrome, and Firefox), this can effectively prevent all Cross-Site Request Forgery attacks throughout your WordPress site.

SameSite cookie flag support was added to PHP on version 7.3, but this plugin ships with a workaround to support all PHP versions WordPress supports.

There is no administrative UI provided: Activate this plugin, and you are all set!

You can configure the SameSite flag value from your WordPress configuration file. You cna pick a value from Lax (default), Strict, or None. You can read about SameSite cookies here.

To configure the SameSite flag value, edit your WordPress configuration file (wp-config.php), and add the following…

Read full description on WordPress.org

Screenshots

Ratings & Reviews

2.511 reviews
5 ★
4
4 ★
0
3 ★
0
2 ★
1
1 ★
6

Compatibility

WordPress6.2+ requiredTested up to 6.3.8
PHP7.0+ required

Top Alternatives to SameSite Cookies

Comment Form CSRF Protection icon
Comment Form CSRF Protection
5500 installsUpdated 2 years ago
ViewCompare
Headit icon
Headit
010 installsUpdated 8 years ago
ViewCompare
View all csrf plugins →

Frequently Asked Questions

Changelog

1.5

  • Fixes a cookie expiration issue that was reported multiple times in the issue queue. Thanks to Jamie Magin (@jamagin at GitHub).
View full changelog on WordPress.org

Contributors

Ayesh KarunaratneAyesh Karunaratne
Plugin Info
Version
2.1
Last Updated
Jul 23, 2023
WP Requires
6.2+
Tested Up To
6.3.8
PHP Requires
7.0+
Active Installs
900
Downloads
23K+
Added
May 2, 2019
Business
Free

Tags

csrfcookiessamesitesecurity

Developer

A
Ayesh Karunaratne
7 plugins0.0M+ total installs
View all plugins →

Quick Compare

SameSite Cookies vs Comment Form CSRF Protection→SameSite Cookies vs Headit→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.