What it checks
Whether responses stop other sites framing the page, with a CSP frame-ancestors directive or the older X-Frame-Options header.
A pass means: Other sites cannot frame these pages.
Possible findings
Pages can be framed by other sites
Severity: LowConfidence: ConfirmedKind: Recommended hardening
What we found
Neither X-Frame-Options nor a CSP frame-ancestors directive is set.
Why it matters
Another site could load your pages in an invisible frame and trick visitors into clicking buttons they cannot see (clickjacking).
How to fix it
Add Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers). If other sites legitimately embed your pages, list them in frame-ancestors.

