GrootMadeGrootMade
Pricing
GrootConnectRegister
Explore allThemesPluginsKitsCollectionsPacksAuthorsCategoriesTagsTrendingDownload PluginPricingResourcesBlogChangelogContact usDocumentationCommunity
GrootMadeGrootMade
ExplorePricingDashboardBlogContact usTermsPrivacy

The WP® trademark is the intellectual property of the WP Foundation, and the Woo® and WooCommerce® trademarks are the intellectual property of WooCommerce, Inc. Uses of the WP®, Woo®, and WooCommerce® names in this website are for identification purposes only and do not imply an endorsement by WP Foundation or WooCommerce, Inc. GrootMade is not endorsed or owned by, or affiliated with, the WP Foundation or WooCommerce, Inc.

Petra

AI assistant for GrootMade

Hi! I'm Petra 👋 Ask me to help you find the perfect WP plugin, theme, or template kit.

Need human help?
Join our DiscordChat on Telegram
Join Discord
ExploreSameSite

SameSite

Adds CSRF protection to site authentication cookies automatically.

Sets the SameSite flag on authentication cookies to block cross-site request forgery attacks. Works across all supported PHP versions without configuration.

Visit SameSite
fv_plugin

SameSite

Adds CSRF protection to site authentication cookies automatically.

Visit site

This plugin automatically adds the SameSite attribute to a site's authentication cookies, providing a foundational layer of protection against Cross-Site Request Forgery (CSRF) attacks. It is designed for site administrators and developers seeking to harden their site's login security without complex setup.

  • Automatic CSRF Protection: Once activated, the plugin modifies authentication cookies to include the SameSite flag, instructing modern browsers to restrict how cookies are sent with cross-site requests. This can prevent many common CSRF attack vectors.
  • Broad PHP Version Support: It includes a polyfill to ensure the SameSite flag functions correctly on all PHP versions the platform supports, not just PHP 7.3 and above where native support was introduced.
  • Zero-Configuration Operation: The plugin works immediately upon activation with sensible defaults. There is no administrative interface to manage, reducing setup time and potential for error.
  • Configurable Flag Values: For advanced use cases, you can define the strictness of the SameSite policy directly in the site's configuration file. Options include Lax (the default balanced setting), Strict, or None.
  • Focused on Authentication: The modification applies specifically to the core authentication cookies. This targeted approach ensures compatibility with other plugins while securing the most critical login sessions.

Note: Its functionality relies on pluggable functions and may be overridden by other plugins that also modify login cookie parameters. Testing via browser developer tools is recommended to confirm it is working in your specific environment.

Package Contents

Package contents information is not available yet.

Version History

No version history available for this item yet.

Comments

No comments yet. Be the first to start the conversation!

Security Scan

More themes and plugins like SameSite

About

Sets the SameSite flag on authentication cookies to block cross-site request forgery attacks. Works across all supported PHP versions without configuration.

  • SameSite
  • v2.1
  • 13 days ago
  • Apr 25, 2026
  • Access: Silver
  • Ayesh Karunaratne
  • Plugin
  • 0
  • No comments