arrow_backBack to resultscontent_paste_goPrefer to do it by hand? Get a copy-paste snippet for your exact stack — also free.
smart_toyFix this with your AI agent
FreeCopy this recipe and paste it into your own coding agent (Claude Code, Codex, Cursor…) to fix “Scammers can embed your site”. The agent works only in your own repo or config — Pazmo is never given access, and there is nothing to unlock.
fix-web-frame-protection.txt · recipe
Task: fix "Frame embedding protection is not visible" on https://example.com. This recipe is FREE. Paste it into your own AI coding agent (Claude Code, Cursor, Codex…). The agent works only in your own repo/config — Pazmo is given no access. What your agent should change (code & config only): 1. Decide whether the service should allow any third-party embedding. 2. Add X-Frame-Options: DENY or SAMEORIGIN, or add a CSP frame-ancestors directive. 3. Collect fresh response-header evidence showing frame protection. Concretely, send this response header on every route: X-Frame-Options: SAMEORIGIN Note: For modern browsers you can instead use a CSP frame-ancestors directive; X-Frame-Options is the widest-supported option. How Pazmo confirms the fix (retest): Sanitized response headers showing X-Frame-Options or CSP frame-ancestors on the public target. Safety: only add the defensive settings above. Don't run other commands, send data anywhere, or make unrelated changes. Review everything before applying.
check_circleYour agent can
- ·Read this recipe and the fix steps
- ·Apply the code/config change in your own repo
- ·Open the change for your review before you ship it
blockYour agent can’t
- ·Change DNS or registrar settings (that stays a human task)
- ·Run unrelated commands or send your data anywhere
- ·Touch anything outside the defensive setting above
Want Pazmo to fix everything in priority order and re-check each one? Verify ownership to unlock the full automated handoff (Pro).