Skip to content

HTTP security

Clickjacking protection checker

See whether another website could load a site's pages inside a frame, by reading the two headers that control it: the Content Security Policy frame-ancestors directive and X-Frame-Options.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

Clickjacking loads a real page from your site in a transparent frame on another site, placed over something the visitor wants to click. The click lands on your page instead, on a button the visitor never saw.

frame-ancestors names who may frame a page: 'none' for nobody, 'self' for your own site, or a list of origins that embed it legitimately. X-Frame-Options is the older header, with two useful values, DENY and SAMEORIGIN. Browsers that understand frame-ancestors ignore X-Frame-Options when both are set, so the CSP directive is the one to get right.

A finding means neither control is set, so any site can frame the page. It is low severity, and matters most on pages where a signed-in visitor can take an action with one click.

How to fix common issues

Pages can be framed by other sites

Add Content-Security-Policy: frame-ancestors 'self' (or X-Frame-Options: SAMEORIGIN for older browsers). If other sites legitimately embed your pages, list them in frame-ancestors.

More in the Clickjacking protection check reference

Scope and limitations

Related guides

Questions

Should I use X-Frame-Options or frame-ancestors?
frame-ancestors, in your Content-Security-Policy header. It is the current standard and can list several allowed origins. Sending X-Frame-Options: DENY or SAMEORIGIN as well does no harm and covers very old browsers.
Can frame-ancestors be set in a meta tag?
No. Browsers ignore frame-ancestors in a meta tag. It only works when sent as an HTTP response header.
A partner embeds our pages. What should we set?
List the partner's origin in frame-ancestors, for example frame-ancestors 'self' https://partner.example. Current browsers give X-Frame-Options no way to allow one specific other site.

Related security tools