What is the PHPSESSID cookie?
Cookie generated by applications based on the PHP language. This is a general purpose identifier used to maintain user session variables. It is normally a random generated number, how it is used can be specific to the site, but a good example is maintaining a logged-in status for a user between pages.
Our October 2026 scan found it on 73 sites (3% of the 2,450 we scanned), set before any consent.
- Purpose
- Functional
- Belongs to
- PHP.net
- Set as
- First-party on 99% of sites, third-party on 1%
- Typical lifetime
- Session (vendor says: Sessions)
Sites that set PHPSESSID before consent
The highest-ranked 30 of 73 sites.
- pubmatic.com1 tracking company
- crpt.ru0 tracking companies
- trueconf.net3 tracking companies
- bitrix24.ru3 tracking companies
- cdnvideo.ru2 tracking companies
- parklogic.com0 tracking companies
- webempresa.eu0 tracking companies
- ddnss.de0 tracking companies
- synology.com1 tracking company
- playrix.com1 tracking company
Show 20 more sites
- pixiv.net3 tracking companies
- flightradar24.com4 tracking companies
- statcounter.com2 tracking companies
- one.com3 tracking companies
- dafont.com2 tracking companies
- dcinside.com2 tracking companies
- julydns.com0 tracking companies
- digikala.com1 tracking company
- lookmovie2.to1 tracking company
- calculator.net0 tracking companies
- funpay.com0 tracking companies
- theblowers.com0 tracking companies
- dogdrip.net3 tracking companies
- ppomppu.co.kr2 tracking companies
- autoplius.lt5 tracking companies
- ss.com0 tracking companies
- skelbiu.lt5 tracking companies
- an1.com0 tracking companies
- kemkes.go.id5 tracking companies
- goal7.co2 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop PHPSESSID being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.