Hi Ramya,here is an example of what to use[1]. When you use AEM6, sightly was created with security by default, so it is automatic.Regards,Opkar[1] http://tostring.me/270/how-to-prevent-cross-site-scripting-xss-attack-on-your-adobe-cq-based-web-application/