WP Anti-Clickjack icon

WP Anti-Clickjack

by Andy Feliciotti

View on WordPress.org
69 Quality Score
Active Installs
16/30

With roughly 4,000 active installs, this is a niche utility rather than a mainstream plugin, and the score reflects that limited reach.

Update Freshness
22/25

The plugin was updated on 2026-01-12 and is tested against WordPress 6.9.4, which signals active upkeep by the author.

User Rating
9/15

A perfect 100 from only 3 ratings is statistically thin, so the true user sentiment is not meaningfully established yet.

Support Health
8/15

Zero support threads opened means either no users have needed help, or the user base is too small to surface issues, making the 50 score appropriately cautious.

WP Compatibility
15/15

The plugin requires WordPress 5.0.0 or higher and is tested up to 6.9.4, so it should work cleanly on any modern install.

Scores higher than 22% of indexed plugins

About

Protect Your WordPress Site From Clickjacking Attacks by Adding the X-Frame-Options Header and Owasp's Legacy Browser Frame Breaking Script.

Active Installs 4k+
Rating ★★★★★ 5/5
Last Updated 2026-01-12 3:11pm GMT
Requires WordPress 5.0.0+
Tested Up To 6.9.7
✓ No known vulnerabilities

What It Does

WP Anti-Clickjack sets the X-Frame-Options HTTP header on your WordPress site to prevent other domains from embedding your pages in iframes. It also injects an older client-side frame-breaking script based on the legacy OWASP approach, which hides page content if the site is rendered inside a frame on older browsers. Together, these two layers aim to stop clickjacking attacks where users are tricked into clicking hidden elements.

Who It's For

This plugin suits administrators of small, compliance-sensitive sites that need a quick, single-purpose clickjacking fix without installing a full security suite. It is best for site owners who have already locked down other attack surfaces and just need to satisfy a specific PCI-DSS or internal audit requirement around frame embedding controls. Non-technical users who want a one-click X-Frame-Options toggle will also find it approachable.

Who Should Skip It

If you already use a major security plugin like Wordfence, Really Simple Security, or Jetpack, skip this: those tools already set X-Frame-Options (or the modern equivalent Content-Security-Policy frame-ancestors directive) out of the box. Anyone running a modern site on recent browsers should also consider a CSP-based solution instead, since the legacy OWASP JavaScript frame buster is a deprecated belt-and-suspenders approach.

The Bottom Line

WP Anti-Clickjack does one thing and does it well, with a recent update and a low minimum WordPress version that should not break anything. However, its tiny install base and essentially no community support mean you are trusting a single developer, and most users are better served by the clickjacking features already built into larger security plugins. Use it only if you specifically need a lightweight, standalone X-Frame-Options solution without the rest of a security suite.

Tags

anti click jacking Browser Frame Breaking Script clickjacking security