WP Anti-Clickjack

WP Anti-Clickjack Install Statistics

-14
79.71%
Today: 55 Yesterday: 69 All-time: 33,144 downloads
WP Anti-Clickjack Icon

Try plugin: WP Anti-Clickjack

We'll create fresh WordPress site with WP Anti-Clickjack installed. You have 20 minutes to test the plugin after that site we'll be deleted.

Takes ~10 seconds to install.

About WP Anti-Clickjack

Protect Your WordPress Site From Clickjacking Attacks by Adding the X-Frame-Options Header and Owasp's Legacy Browser Frame Breaking Script.

2


0


0


0


0

updated: 7 months ago
since: 9 years ago
author: Andy Feliciotti

Description

WP Anti-Clickjack is a powerful security plugin that helps prevent your WordPress site from being vulnerable to clickjacking attacks. Clickjacking is a malicious technique where an attacker tricks users into clicking on a concealed link or button by overlaying it on your legitimate website.

This plugin implements two key defense mechanisms:

  1. X-Frame-Options Header: The plugin adds the X-Frame-Options: SAMEORIGIN HTTP header to your site’s responses. This header instructs web browsers to prevent other websites from embedding your site within an iframe, effectively blocking clickjacking attempts.

  2. OWASP’s Legacy Browser Frame Breaking Script: The plugin includes a modified version of OWASP’s legacy browser frame breaking script. This script prevents other sites from putting your site in an iframe, even in browsers that don’t support the X-Frame-Options header. The script is optimized to work seamlessly in browsers with and without JavaScript enabled.

By combining these two security measures, WP Anti-Clickjack provides comprehensive protection against clickjacking attacks, ensuring the safety and integrity of your WordPress site.

For more information about clickjacking defense techniques, refer to the OWASP Clickjacking Defense Cheat Sheet.

Features

  • Adds the X-Frame-Options: SAMEORIGIN HTTP header to prevent clickjacking
  • Includes a modified version of OWASP’s legacy browser frame breaking script
  • Compatible with popular page builders and editors like Elementor, Divi, WPBakery, and more
  • Provides filters to disable the anti-clickjacking measures when needed
  • Easy to install and configure
  • Regularly updated and tested with the latest WordPress versions

Additional Details

If you need to disable the clickjacking JavaScript on a specific page, you can use the following filter in your theme’s functions.php file:

add_filter('wp_anti_clickjack', '__return_false');

To disable the clickjacking X-Frame-Options HTTP header, use this filter in your theme’s functions.php file:

add_filter('wp_anti_clickjack_x_frame_options_header', '__return_false');