All-in-one free web application security tool. Web application vulnerability and privacy scanner with support for HTTP cookies, Flash, HTML5 localStorage, sessionStorage, CANVAS, Supercookies, Evercookies. Includes a free SSL/TLS, HTML and HTTP vulnerability scanner and URL malware scanner.
X-Frame-Options
HTTP headerInstructs the browser if the current website can be embedded in HTML frame by another website. Since this allows the parent website to control the framed page, this creates a potential for data theft attacks ("clickjacking") and most sensitive websites won't allow them to be framed at all (deny
) or just allow parts of them to be embedded in frames created by themselves only (samesite
).
We have seen 11242 websites setting the
X-Frame-Options
HTTP header and 273 unique values of this header.
DENY
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
DENY
DENY
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
DENY
SAMEORIGIN
SAMEORIGIN
DENY
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN
ALLOW-FROM *
DENY
SAMEORIGIN
SAMEORIGIN
SAMEORIGIN, SAMEORIGIN