SECURITY FINDING
Missing X-Frame-Options header (clickjacking risk)
What it is
Your site can be loaded inside an invisible frame on someone else's page ("clickjacking") — a common trick to make visitors click a real button on your site (follow, buy, change a setting) while believing they're clicking something else.
How to fix it
Add an X-Frame-Options header (or a frame-ancestors rule in your CSP) that denies framing, unless you deliberately embed this site elsewhere. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.