Explanation
How Regex tester works
The regex tester evaluates a regular expression (JavaScript/ECMAScript syntax) against a test text and displays matches, their position and captured groups. Using the flags you control, among other things, global search (g), case sensitivity (i) and multiline behavior (m).
Important for security: a pattern entered by the user can run for an arbitrarily long time due to "catastrophic backtracking". A pure input-length limit does not protect against this. That is why the evaluation runs in a separate Web Worker; if it does not respond within a short time, it is hard-terminated and discarded. The main thread — and thus the operation — always remains responsive.
Limits of this tool
- Only JavaScript regex syntax — PCRE/.NET specifics are missing.
- Blocking patterns are aborted, not "repaired".
- A maximum of 1000 evaluated matches (the first 100 are listed).
Sources
- ECMAScript Specification: RegExp syntax and semantics.
- OWASP: Regular expression Denial of Service (ReDoS).