Clickjacking Poc
A new tool extracted from the codebase.
Last reviewed by the Radiatus Cloud team
Clickjacking PoC Generator
Generate a Proof of Concept (PoC) HTML page to test if a website is vulnerable to Clickjacking (framing attacks).
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Understand and test clickjacking defences
Clickjacking tricks a user into clicking something different from what they perceive, by layering a hidden frame over a decoy. This tool explains clickjacking and helps you check whether a page is protected, so you can confirm your own pages defend against it.
How the attack and defence work
In a clickjacking attack, a malicious page loads your site invisibly in a frame and overlays a decoy, so a click meant for the decoy actually hits your site, potentially triggering an action the user did not intend. The defence is to stop your pages being framed by others, which is done with the X-Frame-Options header or a frame-ancestors directive in a Content-Security-Policy. Checking whether those protections are present tells you whether your pages can be weaponised this way. This is a defensive check on your own site.
Confirm your defences
The tool runs entirely in your browser, so nothing you paste is uploaded, which is exactly what you want when the input is your own security-sensitive data.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What is clickjacking?
An attack that layers your site invisibly over a decoy so a userβs click hits your site instead, triggering an action they did not intend.
How do I defend against it?
By stopping your pages being framed by other sites, using the X-Frame-Options header or a frame-ancestors directive in a Content-Security-Policy.
How does the tool help?
It explains the attack and helps you check whether a page has the framing protections in place, so you can confirm your own pages are defended.
Is this for testing my own site?
Yes. It is a defensive check to confirm your pages cannot be framed and weaponised against your users.
Is my input uploaded?
No. The tool runs entirely in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started β no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.