headers by 0x6a03448f4d
← All headers
Framing

X-Frame-Options / frame-ancestors

Prevent clickjacking.

What it is

Controls whether your page can be embedded in a frame/iframe on another site. The modern control is the CSP frame-ancestors directive; X-Frame-Options is the legacy header.

Why it matters

Stops an attacker from framing your site invisibly and tricking users into clicking things they can't see (clickjacking).

Risk without it

Without it, your authenticated UI can be overlaid under a decoy page and users manipulated into destructive actions.

Recommended

CSP: frame-ancestors 'none' (or 'self'). Legacy fallback: X-Frame-Options: DENY.

Set it

add_header X-Frame-Options "DENY" always;

References