Web Component extending IFrame to bypass X-Frame-Options: deny/sameorigin
-
Updated
Feb 11, 2026 - JavaScript
Web Component extending IFrame to bypass X-Frame-Options: deny/sameorigin
A lightweight JavaScript CORS Reverse Proxy designed to run in a Cloudflare Worker.
NGINX Module for sending security headers
x-frame-options bypass
Websites constantly steal content by iFraming, Unbed stops it in it's tracks.
Build Iframe. Ignore X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, X-Xss-Protection etc.
Remastered web component extending iFrame to bypass X-Frame-Options: deny/sameorigin
The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.
View two sites or two dev servers side by side in one browser window. Sites that block iframes load through a built-in header-stripping proxy.
A set of Asp.Net Core middlewares for adding security headers to ASP.NET Core web apps.
Burp Suite extension for discovering, analyzing, and auditing HTTP security headers including CSP, HSTS, CORS, and web security misconfigurations.
CJChecker is a small command-line tool that checks web applications for basic Clickjacking protection by analyzing HTTP response headers.
Clickjacking automation tool.
Vue directive to bypass X-Frame-Options deny/sameorigin response headers
Audit a URL's HTTP security headers (HSTS, CSP, X-Frame-Options, ...) with a letter grade — runs locally, zero dependencies
Herramienta de auditoria defensiva para detectar vulnerabilidades de clickjacking
Serverless CF Reverse Proxy to bypass same-origin limitations
This scripts will help you to find out vulnerable and outdated libraries from the application also there is script to find out http response headers.
To associate your repository with the x-frame-options topic, visit your repo's landing page and select "manage topics."