How to use this regex backtracking risk check
Enter a pattern and the page tables five structures that make backtracking blow up, marking which ones are present. Press the measure button and it grows the input length step by step and records the real time curve. There is no replace feature here.
How it works, and what the figures are
The checks cover nested quantifiers, a quantifier on an alternation group, overlapping quantifiers in sequence, a backreference used with a quantifier, and a missing start anchor. No score or grade is produced; the page only counts how many are present. Times are measured by running the pattern in this browser as of October 2026, and the growth factor is a plain extension of the measured range.
Limits and cautions
Structural detection is heuristic: it misses real hazards and flags harmless patterns. Results vary by device and engine, and measuring can freeze the browser for several seconds. Do not start with a large repeat count. This page never certifies a pattern as safe.
Frequently asked questions
No. The checks are rough heuristics over the pattern text, so they miss nesting that arises indirectly and they ignore engine-specific optimisations. Even with zero items present a pattern can stall on real input, so read the measured curve and your production logs too.
Backtracking blowups usually happen on failure, not on success, because the engine only concludes failure after trying every possible split. Appending one character that cannot match is the simplest way to expose that worst case.
It stops as soon as a single run passes your threshold. With exponential growth, a few more repeats multiply the time several times over and the browser stops responding. The point where it stopped is itself the warning sign.