X-Frame-Options
X-Frame-Options stops other websites from embedding your site in a hidden frame to trick your users — an attack called clickjacking.
What it is
X-Frame-Options is a response header that controls whether your site is allowed to be loaded inside a frame or iframe on another website. You can block framing entirely, or allow it only from your own domain.
It prevents an attacker from loading your real site invisibly on top of their own, tricking users into clicking things they can't see.
Why it matters
In a clickjacking attack, your site is layered invisibly over a malicious page. A user thinks they're clicking a harmless button, but they're actually clicking something on your site — approving a payment, changing a setting, or confirming an action. X-Frame-Options blocks this by refusing to be framed.
How Pentrawl checks it
Pentrawl checks your response headers for X-Frame-Options. If present, the check passes; if missing, it's flagged as an issue.
How to fix it
Add the X-Frame-Options header to your server configuration. SAMEORIGIN allows framing only by your own site, which is the safest common choice.
X-Frame-Options: SAMEORIGIN