How to use it
- 1
Enter a pattern without slash delimiters and provide JavaScript flags.
- 2
Paste test input and choose a timeout.
- 3
Run the worker, then review matches, captures, and risk signals.
What the tool can do
- JavaScript flags d, g, i, m, s, u, v, and y with duplicate and conflict validation.
- Match ranges, numbered captures, named captures, and optional indices.
- Correct advancement for zero-length global or sticky matches.
- Heuristic review for nested quantifiers, broad wildcards, quantified alternation, backreferences, and large quantifiers.
Common use cases
- Checking a pattern and capture groups before frontend use.
- Comparing flags and zero-length behavior.
- Performing an initial review of a potentially expensive pattern before server-side benchmarking.
How it works inside
Patterns are limited to 2,000 characters, input text to 100,000 characters, and output to 500 matches with bounded previews.
A fresh worker is created for each run, terminated after completion or timeout, and never uses eval or Function construction.
Questions and answers
Does a low-risk review guarantee the pattern is ReDoS-free?
No. You still need adversarial tests and benchmarks in the exact runtime that will execute the pattern in production.
What happens when matching stalls?
The main UI remains responsive, and the dedicated Web Worker is forcibly terminated after the selected timeout.
