WP Clinic
Log in Sign up

SECURITY FINDING

Missing X-Frame-Options header (clickjacking risk)

What it is

Your site can be loaded inside an invisible frame on someone else's page ("clickjacking") — a common trick to make visitors click a real button on your site (follow, buy, change a setting) while believing they're clicking something else.

How to fix it

Add an X-Frame-Options header (or a frame-ancestors rule in your CSP) that denies framing, unless you deliberately embed this site elsewhere. If you're not sure how, install the WordPress Plugin: its Security tab applies fixes like this one automatically.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.