HTTP security
Clickjacking protection checker
See whether another website could load a site's pages inside a frame, by reading the two headers that control it: the Content Security Policy frame-ancestors directive and X-Frame-Options.
What this checks
- The final HTTPS response for the home page of the domain and its
www.name, or the subdomain entered. - A
frame-ancestorsdirective in the enforcedContent-Security-Policyheader. One in a report-only policy does not count. X-Frame-Optionsset toDENYorSAMEORIGIN. Other values, including the obsoleteALLOW-FROM, do not count.- Either control on its own is a pass. Both values are shown, or Not set where a header is absent.
What the result means
Clickjacking loads a real page from your site in a transparent frame on another site, placed over something the visitor wants to click. The click lands on your page instead, on a button the visitor never saw.
frame-ancestors names who may frame a page: 'none' for nobody, 'self' for your own site, or a list of origins that embed it legitimately. X-Frame-Options is the older header, with two useful values, DENY and SAMEORIGIN. Browsers that understand frame-ancestors ignore X-Frame-Options when both are set, so the CSP directive is the one to get right.
A finding means neither control is set, so any site can frame the page. It is low severity, and matters most on pages where a signed-in visitor can take an action with one click.
How to fix common issues
Pages can be framed by other sites
Add Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers). If other sites legitimately embed your pages, list them in frame-ancestors.
Scope and limitations
- It reads the home page only. Pages behind a login, where clickjacking matters most, can send different headers; check them in your browser's developer tools.
- It checks that
frame-ancestorsis present, not what it allows. A directive that permits every origin still passes. - It does not try to frame the page or test whether a particular action could be hijacked.
Related guides
Questions
- Should I use X-Frame-Options or frame-ancestors?
- frame-ancestors, in your Content-Security-Policy header. It is the current standard and can list several allowed origins. Sending X-Frame-Options: DENY or SAMEORIGIN as well does no harm and covers very old browsers.
- Can frame-ancestors be set in a meta tag?
- No. Browsers ignore frame-ancestors in a meta tag. It only works when sent as an HTTP response header.
- A partner embeds our pages. What should we set?
- List the partner's origin in frame-ancestors, for example frame-ancestors 'self' https://partner.example. Current browsers give X-Frame-Options no way to allow one specific other site.
Related security tools
- Content Security Policy checker - Read a site's Content-Security-Policy directive by directive and spot unsafe inline scripts.
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.
- Cookie security checker - Check the Secure, HttpOnly and SameSite attributes of the cookies a home page sets.

