X-Frame-Options / Clickjacking Checker
Check if X-Frame-Options and CSP frame-ancestors block framing.
Paste response headers
Clickjacking analysis
- warnCSP is present but has no frame-ancestors directive.
- goodX-Frame-Options: SAMEORIGIN
Recommended headers
About the X-Frame-Options / Clickjacking Checker
Paste response headers to evaluate whether X-Frame-Options and CSP frame-ancestors actually block your page from being embedded in an iframe, detect conflicts between the two, and get recommended headers.
Examples
No protection
Content-Type: text/htmlOutput
Framing is NOT blockedRelated tools
CORS Config Generator
Security
Generate CORS headers/config for Nginx, Apache, Express, or Workers.
CSP Builder
Security
Build a Content-Security-Policy header from per-directive sources.
Htpasswd Generator
Security
Generate .htpasswd lines using SHA-1 or plain text.
JWT Inspector
Security
Decode a JWT and audit its claims for common issues.
Password Policy Generator
Security
Generate password policy rules, regex and copy for NIST or PCI presets.
Password Strength Checker
Security
Estimate password entropy, crack time, and get actionable advice.
Frequently asked questions
Version 1.0.0 · Updated 2026-08-10 · Runs entirely in your browser