# Content-Security-Policy-Analyzer

> Erkläre eingefügte Direktiven und erkenne häufige Konfigurationsprobleme.

[Open tool](https://www.toolcabana.com/de/content-security-policy-analyzer) · [Datenschutz und Sicherheitswissen](https://www.toolcabana.com/de/category/privacy-and-security-education)

Tool ID: content-security-policy-analyzer. Requested language: de. Description language: de. Complete guide translation: yes.

## Overview (en)

Content Security Policy analyzer splits a pasted CSP into directives and lists each with its values and a review note. It flags 'unsafe-inline', 'unsafe-eval', bare wildcard sources, 'none' combined with other sources, and duplicate directives, and adds rows when object-src, base-uri or frame-ancestors is missing. Results are static heuristics for learning and review.

## Supported tasks (de)

Erkläre eingefügte Direktiven und erkenne häufige Konfigurationsprobleme.

## Steps (de)

1. Füge die Quelle in den Eingabe-Editor ein oder lade das integrierte Beispiel.
2. Prüfe das Quellformat, bevor du den Vorgang ausführst.
3. Führe „Content-Security-Policy-Analyzer“ aus, prüfe die Ausgabe und verwende dann die verfügbaren Bedienelemente zum Kopieren oder Herunterladen.

## Settings

No additional settings.

## Limitations (de)

CSV/XLSX-Eingaben sind auf jeweils 10 MB, 200 Spalten und 20.000 Zeilen begrenzt; die verbundene Ausgabe ist auf 20.000 Zeilen begrenzt. Die Auswertung von JSONPath-Skripten/-Filtern ist deaktiviert. Andere Vorgänge unterliegen ihren sichtbaren Bedienelementen und Textlimits.

## Example input

```text
default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'
```

## Privacy and connections (de)

Dieser Vorgang verarbeitet seine Quelle in deinem Browser. Kopieren und Herunterladen sind ausdrückliche Aktionen; die Quelleingabe wird nicht in einem Konto oder Verlauf gespeichert.

## Questions (de)

### What happens if a CSP has the same directive twice?

The analyzer marks the repeat as a duplicate and notes that browsers use the first occurrence, so values in the later copy are ignored. Merge the sources into a single directive to make the policy behave as intended.

### Why does the CSP analyzer warn that object-src is missing?

object-src, base-uri and frame-ancestors are checked separately as common hardening directives. If one is absent, a row marked missing suggests reviewing whether an explicit restriction is needed; the check does not account for any default-src fallback.

### Should I paste the full header line including Content-Security-Policy:?

Paste only the policy value. Directives are split on semicolons and the first word of each is read as the directive name, so a header prefix would be treated as the first directive's name. Up to 100 directives are accepted.

### Wo wird meine Eingabe verarbeitet?

Dieser Vorgang verarbeitet seine Quelle in deinem Browser. Kopieren und Herunterladen sind ausdrückliche Aktionen; die Quelleingabe wird nicht in einem Konto oder Verlauf gespeichert.

### Welche Eingabelimits gelten?

CSV/XLSX-Eingaben sind auf jeweils 10 MB, 200 Spalten und 20.000 Zeilen begrenzt; die verbundene Ausgabe ist auf 20.000 Zeilen begrenzt. Die Auswertung von JSONPath-Skripten/-Filtern ist deaktiviert. Andere Vorgänge unterliegen ihren sichtbaren Bedienelementen und Textlimits.

## Related tools

- [File encryption and decryption](https://www.toolcabana.com/de/file-encryption-and-decryption)
- [Password strength estimator](https://www.toolcabana.com/de/password-strength-estimator)
- [Sensitive data masking tool](https://www.toolcabana.com/de/sensitive-data-masking-tool)
- [Certificate signing request decoder](https://www.toolcabana.com/de/certificate-signing-request-decoder)
