Skip to content

HTTP security configuration

What is clickjacking protection?

Whether responses stop other sites framing the page, with a CSP frame-ancestors directive or the older X-Frame-Options header.

Part of the External Security Check. Free during the preview.

What it checks

Whether responses stop other sites framing the page, with a CSP frame-ancestors directive or the older X-Frame-Options header.

A pass means: Other sites cannot frame these pages.

Possible findings

Pages can be framed by other sites

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

Neither X-Frame-Options nor a CSP frame-ancestors directive is set.

Why it matters

Another site could load your pages in an invisible frame and trick visitors into clicking buttons they cannot see (clickjacking).

How to fix it

Add Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers). If other sites legitimately embed your pages, list them in frame-ancestors.

References