samyk/evercookie
Produces persistent, respawning "super" cookies in a browser, abusing over a dozen techniques. Its goal is to identify users after they've removed standard cookies and other privacy data such as Flash cookies (LSOs), HTML5 storage, SilverLight storage, and others. observed · 2026-08-28
Health v2 · maintenance only
39/100
- Activity 16
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 5824
- days_rel: n/a
- days_push: 504
- n_releases_24m: 0
Adoption not part of the score
4726 stars · 657 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Evercookie is a JavaScript API that creates extremely persistent, respawning 'super' cookies by storing identifiers across a dozen-plus browser storage mechanisms (HTTP cookies, Flash LSOs, HTML5 storage, ETags, HSTS pinning, canvas, and more). It aggressively recreates deleted cookie data as long as any one storage mechanism remains intact, and can even propagate cookies between browsers on the same machine.
Use cases
- demonstrate how persistent browser tracking works
- test how well privacy tools and browsers resist respawning cookies
- research browser storage mechanisms used for user identification
- educate users on why clearing cookies isn't enough for anonymity
- evaluate anti-tracking extensions against supercookie techniques
When to choose
- you need a well-known reference implementation of persistent-cookie techniques for research or education
- you want to audit privacy software against a wide range of storage-based tracking vectors
- you're demonstrating tracking risks to non-technical audiences
When to avoid
- you want to actually track users in production - many mechanisms (Flash, Silverlight, Java, IE userData) are obsolete and it's ethically and often legally problematic
- you need a supported, licensed dependency - the repo has no license
- you're building privacy-respecting analytics or consent-compliant identification
- you need modern browser support - several techniques no longer work in current browsers
Facets
library · maturity maintenance
security privacy http-client middleware privacy security web-development browser-extensions browser tracking cookies fingerprinting demonstration privacy-research persistent-identification javascript web-server
2 sources
- readme: https://github.com/samyk/evercookie · fetched 2026-08-28 · 1d1de9832903
- homepage: https://samy.pl/evercookie/ · fetched 2026-08-29 · cb3b03b79bf4
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| samyk/evercookie | main | 39 |
For agents
markdown · JSON · MCP: product_card(name="samyk/evercookie")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem