Add proper checks to handle XSS attacks and CSRF on your site.
Docs Cross-Site Request Forgeries XSS cheat sheet DOM based XSS cheat sheet
Tools Free XSS scanner