I am testing an express app, and if I scan it with nikto I get these results:
"+ The anti-clickjacking X-Frame-Options header is not present. + Th