Update Javascript to use a newer, OWASP-recommended method. Add support for the X-Frame-Options HTTP response header.