Framing
X-Frame-Options / frame-ancestors
Prevent clickjacking.
What it is
Controls whether your page can be embedded in a frame/iframe on another site. The modern control is the CSP frame-ancestors directive; X-Frame-Options is the legacy header.
Why it matters
Stops an attacker from framing your site invisibly and tricking users into clicking things they can't see (clickjacking).
Risk without it
Without it, your authenticated UI can be overlaid under a decoy page and users manipulated into destructive actions.
Recommended
CSP: frame-ancestors 'none' (or 'self'). Legacy fallback: X-Frame-Options: DENY.
Set it
add_header X-Frame-Options "DENY" always;