Loads any URL in a frame and reports whether it can be framed.
Same-origin targets are verified directly (the frame's document is
readable). For cross-origin targets the browser blocks all inspection, so a
visible frame is the proof — the browser refuses to render pages that send
X-Frame-Options: DENY / Content-Security-Policy:
frame-ancestors 'none'. Bonus: when the target allows CORS, its
anti-framing headers are read and shown above.