Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The reliable way to find out whether your WordPress website uses cookies is to inspect cookies stored for its domain in a browser. In Chrome, open DevTools, go to Application > Storage > Cookies, select the site’s origin, and review the entries. Check additional pages and visitor states—especially logged-in sessions and pages with embedded services—because one page load is only a snapshot of the site’s cookie behavior.

Check your WordPress site’s cookies in Chrome

  1. Open the WordPress website in Chrome.
  2. Open Chrome DevTools. You can right-click the page and choose Inspect, or use Chrome’s DevTools keyboard shortcut.
  3. Select the Application panel.
  4. In the sidebar, expand Storage, then open Cookies.
  5. Select the site’s origin, such as its HTTPS domain. Chrome displays the cookies currently stored for that origin.
  6. Review each entry’s name, domain, path, and Expires / Max-Age value. Chrome also exposes fields such as HttpOnly and Secure.

What the cookie columns tell you

Field What it tells you
Name The identifier assigned to the cookie. Names can suggest a WordPress function or a third-party service, but a name alone does not prove its purpose.
Domain The host or hosts that can receive the cookie. A cookie from an embedded or external domain may not appear under your main site’s origin.
Path The URL path for which the browser sends the cookie. A path limited to an administration area may not affect ordinary visitors.
Expires / Max-Age Whether the cookie is temporary or persists until a stated date or duration. A session cookie generally has no persistent expiration date.
HttpOnly Whether client-side JavaScript is prevented from reading or modifying the cookie. An HttpOnly cookie can still be sent by the browser.
Secure Whether the browser restricts the cookie to secure connections.

Repeat the check for the states visitors actually use

The cookie list can change after navigation or an action, so inspect more than the homepage.

  • Open important public pages, such as a shop, membership area, contact form, or video page, and check the list again.
  • Run the check while logged out, then repeat it after logging in. WordPress authentication and administration cookies may appear only for logged-in users.
  • Load pages containing videos, social widgets, maps, advertising, analytics, or other embedded services. Those services can set cookies under their own domains.
  • Repeat after actions that change behavior, such as submitting a form, changing a preference, or opening a consent banner.

Record the cookie name, domain, path, expiration, and the page or action that caused it to appear. That produces a site-specific record of the states you examined, not a guaranteed inventory of every possible page or visitor.

Inspect cookies attached to a specific request

To see which cookies were involved in one network transaction, open DevTools’ Network panel, select a request, and open its Cookies tab. This is useful when a cookie appears during an AJAX call, login request, redirect, or embedded service load and you need to connect it to a particular request rather than merely seeing it in storage.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Glade PlugIns Refills Air Freshener Starter Kit, Scented and Essential Oils for Home and Bathroom, Cookie Caramel Rush, 0.67 Fl Oz, 1 Warmer + 1 Refill
  • Sweeten the air with Cookie Caramel Rush, with notes of vanilla cookie and caramel​
  • Set a festive mood with Christmas scents from our Limited Edition Holiday Fragrance Collection
  • Change the mood with our most adjustable warmer ever (vs. previous Glade plugin air freshener, on low setting) and get cozy with long lasting fragrance
  • Glade is America’s #1 selling holiday fragrance brand* (*Based on Nielsen sales data Total USxAOC ending Dec 2020)
  • Glade air freshener fragrance is consciously crafted by master perfumers and infused with essential oils
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Cookies WordPress core may set

WordPress core documents cookies used for authentication and user-related functions. The exact names include a site-specific hash or user identifier, so the entries on your installation may not match these examples character for character.

Documented example Typical role Duration qualification
wordpress_[hash] Authentication in the administration area. Controlled by authentication settings and filters; do not assume a universal lifetime.
wordpress_logged_in_[hash] Indicates that a user is logged in. Depends on the login’s remember setting and site configuration.
wp-settings-{time}-[UID] Stores user-specific preferences for the administration interface and, in some cases, the main site interface. Configured by WordPress and potentially affected by site behavior.

WordPress’s wp_set_auth_cookie() developer reference documents a persistent-cookie default of 14 days when Remember Me is used. Without that option, the login is described as a browser-session cookie; the authentication expiration defaults are filterable, and site code can change them. These are function defaults, not a promise about the duration on every website.

Why your site’s list is different from another WordPress site

WordPress core does not determine every cookie on an installation. Themes and plugins can add cookies for features such as shopping carts, memberships, forms, analytics, advertising, or personalization. Embedded third-party content can also set cookies and collect information outside the site’s direct control.

Consequently, a cookie table published for one WordPress site— including WordPress.org—should be treated as that site’s example, not as the cookie list for your website. The purpose of an unfamiliar cookie may require checking the plugin, theme, embedded provider, or server response that created it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why document.cookie is not enough

Running document.cookie in the console shows only cookies accessible to JavaScript for the current document. It does not provide a complete inventory: HttpOnly cookies are deliberately unavailable to JavaScript, and cookies scoped to another domain or path may not be returned. Use DevTools’ Application storage view and, when necessary, the Network request’s Cookies tab instead.

Quick Recap

Bestseller No. 1

A practical coverage checklist

  • Check the site’s origin under Application > Storage > Cookies.
  • Review name, domain, path, expiration, HttpOnly, and Secure fields.
  • Test both logged-out and logged-in states when the site supports accounts.
  • Visit feature pages and load embedded content.
  • Repeat after meaningful visitor actions.
  • Use the Network panel to associate a cookie with a particular request.
  • Do not present the result as universal unless you have checked all relevant pages, user states, and external services.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.