Fix today
Your page contains an invisible embedded window
This is the exact wording EverThread uses when it finds this on a customer's site, written for someone who runs a business, not a server. The example site here is yourbakery.com.
What we saw
A hidden frame loads https://cdn-stat-track.example/frame.html where visitors cannot see it.
Why it matters
Invisible frames are a common way hacked sites load ads, miners or phishing kits without the owner noticing.
How to fix it
If nobody added this on purpose, your site may be compromised. Ask your developer to remove it and find how it got in.
For your developer
Hidden iframe src=https://cdn-stat-track.example/frame.html (1x1). Remove; audit templates, plugins and database for injection.