The X-FRAME-OPTIONS sets a restriction on the framing of a web page for a particular domain. It uses the value DENY
and SAMEORIGIN for rendering the contents into a child frame. It is possible to stop the rendering completely in
a child frame using DENY as a parameter. The SAMEORIGIN parameter declares that the content can only come
from the parent site and that no third party content rendering is allowed.
This addon scans all the HTTP response headers that accompany with the web page and raises a notification in the status bar showing whether the declarative security for Clickjacking is applied on the respective domain or not.
For more details Refer: http://www.usenix.org/event/collsec10/tech/full_papers/Sood.pdf