← All guides

PHP sessions: only use when state is really needed

A PHP session is a visitor recognition for a limited period of time. It makes sense when an application needs status across multiple requests, but is usually unnecessary for a purely static page or a simple page view counter.

Do not start session automatically

session_start() only use in functions that actually require session state. Otherwise, an identifier and often a session cookie are created for no functional reason.

Limit lifetime

Set cookie lifetime and server-side garbage collection to suit the purpose. Do not keep personal data in session storage longer than necessary.

Secure cookie

Use HTTPS for necessary sessions and configure cookie attributes such as Secure, HttpOnly and an appropriate SameSitevalue. However, security does not replace the question of whether the session is even needed.

overall check

For cookies and other storage mechanisms, also use the check checklist and evaluate the session cookie, server-side session data and storage separately.

Requirements

Clarify beforehand which pages or functions really require server-side session state and which session data is currently being saved.

Dismantling

If a function does not work correctly without a session, reactivate session start only for this process and limit the lifespan and stored content again.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑