Just adding the sandbox attribute is enough to severely lock down an iframe.
<iframe sandbox src="http://example.com"></iframe>
<iframe sandbox src="http://example.com"></iframe>
There's also ' frame-src' for content security policies, which lets you control what is allowed in the iframe's src. Even with these guards in place, you generally should not let user content drive an iframe's src
[0] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...