https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
http://speckyboy.com/2012/05/13/six-common-web-programming-mistakes-and-how-to-avoid-them/