I feel good. Just do not store the password or sensitive data in the session if someone has stolen the session ID. I believe that most of the security risks arise when a password is securely received on the server.
In addition, you should keep your hashed password at a minimum. Do this (assuming $ user-> password hashed using sha1)sha1($password) == $user->password
source
share