Session IDs as Query Parameters Must Die
Purge those nasty JSESSIONID and PHPSESSID parameters from the URL bar. Now. Sensitive data in GET parameters are bad. Even over HTTPS.
Check out this session ID killer proxy built on nginx, that converts these sensitive query parameters into safe and secure cookies.
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed