Skip to main content
New: 190 SEO checks now available. See what's new
mediumSecurityX_FRAME_OPTIONS_MISSING

X-Frame-Options header missing — the fix

This site does not send the X-Frame-Options HTTP header, which controls whether the page can be embedded in iframes on other domains. Without it, the page is vulnerable to clickjacking attacks.

Where this fits: security in SEO

Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.

Why x-frame-options header missing hurts your rankings

Clickjacking attacks overlay your page in a transparent iframe, tricking users into clicking elements on your site while believing they are interacting with another site. This can lead to unauthorized actions, data theft, and account compromise. A security breach can result in Google Safe Browsing warnings that devastate organic traffic.

This is a medium-severity issue: individually modest, but it compounds — dozens of medium issues across hundreds of pages add up to a real quality deficit in how search engines assess the site.

How to fix it

Add the X-Frame-Options header to your server responses. Use DENY to prevent all framing, or SAMEORIGIN to allow framing only from your own domain. For more granular control, use the Content-Security-Policy frame-ancestors directive.

# Prevent framing entirely
X-Frame-Options: DENY

# Or allow same-origin framing only
X-Frame-Options: SAMEORIGIN

Security best practices

  • Serve everything over HTTPS and redirect HTTP with a single 301.
  • Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
  • Eliminate mixed content — one insecure asset breaks the padlock.
  • Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
  • Monitor Search Console's security section — Google often knows you're hacked before you do.

The full library: SEO best practices, by category.

Frequently asked questions

What does "X-Frame-Options header missing" mean?

This site does not send the X-Frame-Options HTTP header, which controls whether the page can be embedded in iframes on other domains. Without it, the page is vulnerable to clickjacking attacks.

Why does x-frame-options header missing matter for SEO?

Clickjacking attacks overlay your page in a transparent iframe, tricking users into clicking elements on your site while believing they are interacting with another site. This can lead to unauthorized actions, data theft, and account compromise. A security breach can result in Google Safe Browsing warnings that devastate organic traffic.

How do I fix x-frame-options header missing?

Add the X-Frame-Options header to your server responses. Use DENY to prevent all framing, or SAMEORIGIN to allow framing only from your own domain. For more granular control, use the Content-Security-Policy frame-ancestors directive.

How serious is this issue?

This is a medium-severity issue: individually modest, but it compounds — dozens of medium issues across hundreds of pages add up to a real quality deficit in how search engines assess the site. It belongs to the security family of checks.

How do I find every page affected by this on my site?

Run a free Dr Urls audit: it crawls your site, detects x-frame-options header missing on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.

Does your site have this issue?

A free Dr Urls audit crawls your site, finds every page affected by x-frame-options header missing, and hands you a ready-made fix task.

Check my site free

Related security guides