Test X-Frame-Options and CSP frame-ancestors (CWE-1021)
Legacy header that controls whether a page can be displayed in an iframe.
Modern directive that supersedes X-Frame-Options with more control.
Clickjacking is an attack where a malicious site tricks users into clicking on something different from what they perceive, by overlaying transparent frames over legitimate content.