PHP sessions: only use when state is really needed
A PHP session is a visitor recognition for a limited period of time. It makes sense when an application needs status across multiple requests, but is usually unnecessary for a purely static page or a simple page view counter.
Do not start session automatically
session_start() only use in functions that actually require session state. Otherwise, an identifier and often a session cookie are created for no functional reason.
Limit lifetime
Set cookie lifetime and server-side garbage collection to suit the purpose. Do not keep personal data in session storage longer than necessary.
Secure cookie
Use HTTPS for necessary sessions and configure cookie attributes such as Secure, HttpOnly and an appropriate SameSitevalue. However, security does not replace the question of whether the session is even needed.
overall check
For cookies and other storage mechanisms, also use the check checklist and evaluate the session cookie, server-side session data and storage separately.
Requirements
Clarify beforehand which pages or functions really require server-side session state and which session data is currently being saved.
Dismantling
If a function does not work correctly without a session, reactivate session start only for this process and limit the lifespan and stored content again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.