com.gumballtools/regex-explainer

Regex Explainer

Explain a regex in plain English and detect catastrophic backtracking risk.

0.1.0
Version
remote
Transport
1
Tools

Security review

Review passed

Reviewed 23h ago.

  • tools: 1 tools scanned
  • metadata: scanned

No findings.

Tools (1)

  • explain_regex

    Explain a regular expression in plain English and detect the failure modes that make patterns dangerous rather than merely wrong. Use this whenever a regex needs to be read, reviewed, or verified — and ALWAYS before putting a pattern somewhere it will run against untrusted input. The critical check is catastrophic backtracking: a pattern like (a+)+$ is three characters longer than a safe equivalent, looks harmless, and takes minutes of CPU on a 30-character input that almost matches. That makes it a denial-of-service vector. Whether a pattern is vulnerable depends on whether nested quantifiers can match the same characters in more than one way, which is a structural property that is unreliable to judge by reading. It also flags: missing anchors (an unanchored validator accepts any string that merely CONTAINS a valid value), unescaped dots, character ranges like [A-z] that span punctuation, alternation precedence mistakes where an anchor applies to only one branch, and constructs Java