Barrion Docs
Passive Scanning

Clickjacking Protection

What Barrion checks when it evaluates whether your site can be embedded in other websites without your permission.

Barrion checks whether your site is protected against clickjacking, an attack where a malicious website embeds your application invisibly inside a frame, tricking users into unknowingly clicking your buttons or links.

What Barrion Checks

Frame Security Policy

Barrion checks whether your site prevents other websites from embedding it in a frame or iframe. This protection is provided by either the X-Frame-Options header or a frame-ancestors directive in your Content Security Policy. Either one is sufficient to pass this check.

Severity: High

A site without frame protection can be loaded invisibly inside a malicious webpage. Attackers overlay their own content on top, causing users to interact with your application without realizing it, potentially taking actions like transferring funds, changing account settings, or approving permissions.

What to Do

Frame protection is configured at the server or application level. Share this finding with your developer or hosting provider. The fix involves adding a single HTTP header, which is a low-effort, high-impact change. Barrion's AI recommendations can generate the specific configuration needed for your setup.