arrow_backBack to results

smart_toyFix this with your AI agent

Free

Copy this recipe and paste it into your own coding agent (Claude Code, Codex, Cursor…) to fix Scammers can embed your site. The agent works only in your own repo or config — Pazmo is never given access, and there is nothing to unlock.

fix-web-frame-protection.txt · recipe
Task: fix "Frame embedding protection is not visible" on https://example.com.

This recipe is FREE. Paste it into your own AI coding agent (Claude Code, Cursor,
Codex…). The agent works only in your own repo/config — Pazmo is given no access.

What your agent should change (code & config only):
1. Decide whether the service should allow any third-party embedding.
2. Add X-Frame-Options: DENY or SAMEORIGIN, or add a CSP frame-ancestors directive.
3. Collect fresh response-header evidence showing frame protection.

Concretely, send this response header on every route:
  X-Frame-Options: SAMEORIGIN
  Note: For modern browsers you can instead use a CSP frame-ancestors directive; X-Frame-Options is the widest-supported option.

How Pazmo confirms the fix (retest):
  Sanitized response headers showing X-Frame-Options or CSP frame-ancestors on the public target.

Safety: only add the defensive settings above. Don't run other commands, send data
anywhere, or make unrelated changes. Review everything before applying.
content_paste_goPrefer to do it by hand? Get a copy-paste snippet for your exact stack — also free.

check_circleYour agent can

  • ·Read this recipe and the fix steps
  • ·Apply the code/config change in your own repo
  • ·Open the change for your review before you ship it

blockYour agent can’t

  • ·Change DNS or registrar settings (that stays a human task)
  • ·Run unrelated commands or send your data anywhere
  • ·Touch anything outside the defensive setting above

Want Pazmo to fix everything in priority order and re-check each one? Verify ownership to unlock the full automated handoff (Pro).