Articles ยท Developer Tools
Test a regex without freezing the tab
A nested (a+)+ against a long string of a’s is a classic way to hang a page. Online testers that run RegExp on the main thread make that your problem. Heuristics that flag nested quantifiers, repeated .*, and quantified overlapping alternation will not catch every ReDoS, but they catch the ones that show up in code review. Matching belongs in a worker you can terminate.
Why this is worth doing in the browser
DevNestro’s Regex Safety & Performance Inspector does not execute your pattern on the UI thread for the test action. A same-origin worker runs the match with a cap on sample size and match count. If it does not finish within 800 ms, the worker is terminated and you get an error instead of a frozen tab. Inspect-only looks at the pattern text for known traps and compiles it once to see if it is valid. JavaScript and .NET engines differ; a “safe here” result is not a proof for production servers. Unicode samples are allowed. Analytics does not record the pattern or the sample.
How to use the tool
Enter a pattern, inspect, paste a sample, test with timeout, cancel if needed, clear to drop worker state. Related JSON Formatter and Data Converter help when the next step is structured text, not a regex.
- Inspect before you test a pattern you copied from a forum.
- Keep samples bounded; the tool refuses oversized input.
- Treat a timeout as a warning, not as a pass.
- Do not paste secrets into the sample if you can avoid it.
Privacy
Pattern and sample stay in this browser. They are not uploaded to DevNestro and are not sent to analytics. No regex engine is downloaded from a third party for this tool.
Need to try a scary regex? Open the inspector, run it in a worker, and stop it if it takes too long.