Just add HTTP-CORS-HEADER
x-frame-options:Allow-From: https://webvisor.com https://metrika.yandex.ru

If you want more options, use https://www.drupal.org/project/seckit

Supporting organizations: 

Project information

Releases