function validateClickEvent(e) {
var r = e.target.getBoundingClientRect();
if (e.x >= r.left && e.x <= r.right && e.y >= r.top && e.y <= r.bottom) {
console.log('looks legit');
} else {
console.log('faked click');
}
}
Set this as the click handler. The click method is browser specific, but on Chrome the x/y coordinates on the event will be incorrect. A smarter script could fool this, though.