consider https://github.com/nelmio/NelmioSecurityBundle for use in ClickJack protection see \Zikula\Bundle\CoreBundle\EventListener\ClickjackProtectionListener https://dev.to/jszutkowski/applying-content-security-policy-in-symfony-to-reduce-xss-risks-5a4l refs #3712