URL to test:
Your page is embedded below using an iframe tag. If it loads, you may be vulnerable to clickjacking attacks. Use a Content Security Policy with the default-src or frame-ancestors directive or set the X-Frame-Options header.