How to Fix Secure Cookie Flag Missing WordPress Login Page
If a security scanner reports secure cookie flag missing on your WordPress login page, it is worth investigating. Authentication cookies are an important part of WordPress security because they help keep users logged in securely after they enter their credentials.
The good news is that this warning does not always mean your WordPress installation has been hacked or seriously compromised. In many cases, the underlying problem is related to HTTPS configuration, WordPress incorrectly detecting SSL, a reverse proxy, CDN, or server configuration.
In this guide, we’ll explain how to fix secure cookie flag missing WordPress login page issues safely, even if you’re not an experienced WordPress developer.
We’ll start with the basics, then work through the most common causes and solutions.

The Core Basics
A secure cookie is a browser cookie that is instructed to travel only over an encrypted HTTPS connection. This is particularly important for authentication cookies because they can be associated with a user’s logged-in WordPress session.
WordPress uses several cookies for authentication. For HTTPS logins, WordPress uses a secure authentication cookie such as `wordpress_sec_[hash]`. WordPress documentation strongly recommends HTTPS for login security. ([WordPress Developer Resources][1])
The Secure flag tells the browser that the cookie should only be transmitted through HTTPS. Without it, a cookie may potentially be exposed if it is transmitted over an unencrypted HTTP connection.
There is another important piece of the puzzle: WordPress needs to correctly recognise that your website is using HTTPS. WordPress determines SSL status through functions such as `is_ssl()`, and authentication cookies use that information when deciding whether they should be secure. ([WordPress Developer Resources][2])
This means a website can have a perfectly valid SSL certificate while WordPress still incorrectly believes the connection is HTTP.
That situation is particularly common when a website uses a CDN, reverse proxy, load balancer, or other service that handles HTTPS before passing the request to the WordPress server.
💡 WP Fix It Co Recommendation: If you’re trying to fix secure cookie flag missing wordpress login page warnings, having fast, secure WordPress hosting with properly configured HTTPS can make the process much easier and help prevent SSL and server-configuration problems from causing the issue in the first place. Get Hostinger WordPress Hosting here.
How to Fix Secure Cookie Flag Missing WordPress Login Page
1. Confirm Your WordPress Site Uses HTTPS
Start with the simplest check.
Open your website in a browser and look at the address bar.
Your website should load using:
`https://yourdomain.com`
rather than:
`http://yourdomain.com`
Also test the login page directly:
`https://yourdomain.com/wp-login.php`
If the login page loads through HTTP, your first priority should be properly configuring HTTPS.
WordPress recommends HTTPS for protecting both administrator logins and visitors. ([WordPress Developer Resources][3])
Check **Settings → General** inside WordPress and make sure both:
* WordPress Address (URL)
* Site Address (URL)
use `https://`.
Don’t simply change these URLs if your SSL certificate isn’t working correctly. Doing so prematurely can create login or redirect problems.

2. Check Your SSL Certificate
A valid SSL certificate is essential.
Visit your website using HTTPS and check whether your browser reports a secure connection.
If you see certificate warnings, expired certificates, hostname mismatches, or other TLS errors, fix those problems before troubleshooting WordPress cookies.
Your hosting provider should be able to help if the certificate isn’t being issued or renewed correctly.
3. Force WordPress Administration Over HTTPS
WordPress provides the `FORCE_SSL_ADMIN` constant specifically for securing logins and the administration area.
Open your `wp-config.php` file and, if appropriate for your setup, add:
“`php
define( ‘FORCE_SSL_ADMIN’, true );
“`
This should normally be placed before the line:
“`php
/* That’s all, stop editing! Happy publishing. */
“`
WordPress documentation confirms that `FORCE_SSL_ADMIN` forces administration screens and logins to use SSL. ([WordPress Developer Resources][4])
Important: Your server must already have working HTTPS before enabling this setting. WordPress specifically warns that SSL must be configured on the server first. ([WordPress Developer Resources][3])
4. Check Whether WordPress Correctly Detects HTTPS
This is one of the most important steps.
You can have HTTPS working perfectly in your browser while WordPress internally thinks the request is HTTP.
This commonly happens with:
* Cloudflare
* Reverse proxies
* Load balancers
* CDN services
* Some managed hosting environments
* SSL termination at another server
WordPress’s `is_ssl()` function determines whether SSL is being used, but WordPress notes that some proxy and load-balancer configurations can cause problems with this detection. ([WordPress Developer Resources][2])
If you’re behind a reverse proxy, your server may need to pass the original HTTPS protocol information to WordPress.
For some environments, WordPress documents a configuration such as:
“`php
if ( isset( $_SERVER[‘HTTP_X_FORWARDED_PROTO’] ) && ‘https’ === $_SERVER[‘HTTP_X_FORWARDED_PROTO’] ) {
$_SERVER[‘HTTPS’] = ‘on’;
}
“`
This should be placed in `wp-config.php` before WordPress loads its main configuration file.
However, don’t blindly copy proxy-specific code into every WordPress installation. Your hosting, CDN, and server configuration determine the correct approach.
If you’re unsure, ask your hosting provider whether HTTPS is being terminated at a proxy and whether `HTTP_X_FORWARDED_PROTO` is being passed correctly.
5. Check Your Browser’s Cookies
After making changes, test the actual cookie rather than relying solely on a security scanner.
Open your browser’s developer tools and locate the site’s cookies.
Depending on your browser, you can normally find them under an area such as:
Application/Storage → Cookies
Look for WordPress authentication cookies after logging in.
The important security attributes can include:
* Secure
* HttpOnly
* SameSite
The Secure attribute should be present for authentication cookies when the login is operating over HTTPS.
WordPress’s authentication-cookie system uses the SSL status detected by WordPress when deciding whether authentication cookies should be secure. ([WordPress Developer Resources][5])
6. Clear Old Cookies and Test Again
After changing SSL or WordPress configuration, your browser may still contain old cookies.
Clear the cookies for your website, close the browser tab, and open the login page again.
Then log back in.
Test the cookie again.
This simple step can prevent you from troubleshooting a problem that is actually caused by an old browser session.
7. Temporarily Check Plugins and Security Software
Security, caching and cookie-management plugins can sometimes modify authentication behaviour.
If the secure flag remains missing after checking HTTPS and server configuration, consider whether a plugin is modifying cookies or login functionality.
Potentially relevant plugin categories include:
* Security plugins
* Cookie-consent plugins
* Caching plugins
* Login-management plugins
* Membership plugins
* CDN integration plugins
Don’t immediately disable everything on a live production website.
Instead, use a staging environment where possible. If necessary, temporarily deactivate suspected plugins one at a time and retest.
8. Check Caching Rules
Your WordPress login page should not normally be treated like an ordinary publicly cacheable page.
Caching `wp-login.php` or authenticated sessions incorrectly can cause unusual login behaviour, stale responses and cookie-related problems.
WordPress specifically recommends checking server caching and excluding `wp-login.php` and cookie-based sessions where appropriate. ([WordPress Developer Resources][1])
Check your:
* WordPress caching plugin
* Hosting cache
* CDN cache
* Reverse proxy
* Server-level caching
After changing cache rules, purge the relevant caches before testing again.
Best Practices and Pro Tips
The best solution isn’t simply to make a security scanner stop complaining. You want the entire login environment configured correctly.
Keep WordPress, plugins and themes updated, and always use HTTPS throughout the website.
Avoid adding random cookie-related PHP snippets from forums without understanding what they change. A poorly written cookie filter can interfere with authentication or create unexpected login problems.
If you use Cloudflare, a CDN, reverse proxy or load balancer, document how HTTPS travels from the visitor to the WordPress server. The critical question is whether WordPress correctly understands that the original visitor connection was HTTPS.
WordPress itself uses `is_ssl()` when determining the default security state of authentication cookies, which is why correct HTTPS detection is so important. ([WordPress Developer Resources][2])
Finally, test the website in a private/incognito browser window after making security changes.
Common Mistakes to Avoid
1. Installing a plugin immediately
You may not need another plugin. The problem could simply be an incorrectly configured HTTPS or proxy environment.
2. Forcing HTTPS before SSL works
Don’t enable `FORCE_SSL_ADMIN` on a website whose HTTPS configuration is broken. This can lead to redirects or an inaccessible login page.
3. Ignoring reverse proxies
If HTTPS is handled by a CDN or proxy, WordPress may not automatically recognise the original secure connection correctly.
4. Testing without clearing cookies
Old authentication cookies can make it appear as though your changes haven’t worked.
5. Ignoring caching
A cached login response can produce confusing results even after you’ve corrected the underlying configuration.
Conclusion: Fix Secure Cookie Flag Missing WordPress Login Page Issues
When you need to fix secure cookie flag missing WordPress login page warnings, start with the fundamentals rather than immediately installing another security plugin.
Confirm HTTPS works correctly, verify your WordPress URLs, consider enabling `FORCE_SSL_ADMIN`, and investigate whether a CDN, reverse proxy or hosting configuration is preventing WordPress from correctly detecting HTTPS. WordPress’s own documentation confirms that secure administration and login depend on a properly configured SSL environment. ([WordPress Developer Resources][4])
Once you’ve corrected the underlying configuration, clear your cookies, purge caches and test the login page again.
For more practical WordPress troubleshooting guides, security fixes, hosting advice and beginner-friendly technical solutions, keep visiting WP Fix It Co.