Cookies set without the Secure flag
warningThese cookies are set without the Secure flag: ATTRIBUTION_V1, me, visitorid. That means the browser will also send them over plain HTTP, where anyone on the same network can read them — including session cookies, which is enough to hijack a logged-in account.