security / security headers / x-frame-options
Security headers

X-Frame-Options

X-Frame-Options stops other websites from embedding your site in a hidden frame to trick your users — an attack called clickjacking.

Severity if missing
Medium
Category
Security headers
Standard
RFC 7034

What it is

X-Frame-Options is a response header that controls whether your site is allowed to be loaded inside a frame or iframe on another website. You can block framing entirely, or allow it only from your own domain.

It prevents an attacker from loading your real site invisibly on top of their own, tricking users into clicking things they can't see.

Why it matters

In a clickjacking attack, your site is layered invisibly over a malicious page. A user thinks they're clicking a harmless button, but they're actually clicking something on your site — approving a payment, changing a setting, or confirming an action. X-Frame-Options blocks this by refusing to be framed.

The risk
Without this header, attackers can embed your site invisibly and trick logged-in users into performing actions without realising it.

How Pentrawl checks it

Pentrawl checks your response headers for X-Frame-Options. If present, the check passes; if missing, it's flagged as an issue.

How to fix it

Add the X-Frame-Options header to your server configuration. SAMEORIGIN allows framing only by your own site, which is the safest common choice.

Recommended
X-Frame-Options: SAMEORIGIN
Check your domain's X-Frame-Options in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →