Cookies set without the Secure flag
warningThese cookies are set without the Secure flag: localization, cart_currency, _shopify_y, _shopify_s. That means the browser will also send them over plain HTTP, where anyone on the same network can read them — including session cookies, which is enough to hijack a logged-in account.