Any setting to avoid XSS? e.g. Maintain a list of allowed URIs about JavaScript/ifram source, and others are all denied.