All fix guides

Ad tracking (C3c)

Attribution cookies, including HttpOnly cookies

What this check means

This guide helps you act on one scan finding. It is not legal advice or a compliance verdict.

What to fix

HttpOnly attribution cookies are set server-side. Safe changes need someone who can edit the cookie write path and header policy.

This one needs a developer

Editing Set-Cookie, HttpOnly, and SameSite behavior on WordPress usually means a mu-plugin, reverse-proxy rule, or host config. That is not a safe copy-paste wp-admin click-path.

See WordPress care plans

Confirm it is fixed

After the cookie write path is updated, re-scan and compare attribution cookies (C3c).

Rescan this check on your site

Scan the same URL again, then compare this check with your previous report.

Run a free leak scan