Regex Backtracking Visualizer
Runs a small backtracking regex engine — the same strategy Perl, Python, Java and JavaScript use — one step at a time, showing the current position in the pattern and in the input, the backtrack stack depth, and a running step counter. Feed it (a+)+b and a string of a's with no b, and watch the step count double with every extra character: that is catastrophic backtracking, the bug behind real-world ReDoS outages. A plot mode measures steps against input length so you can see the exponential curve, and presets load famous evil patterns. The engine supports literals, ., character classes, groups, alternation and the *, +, ? quantifiers.
Runs 100% in your browser — nothing you paste leaves your device.
Read the full guide to this tool
Notes
- Supported syntax: literals, ., [abc], [^a-z], (), |, *, +, ? and escapes like \d \w \s. No anchors, backreferences or lazy quantifiers — the subset is enough to reproduce every classic catastrophic case.
- (a+)+b on "aaaaaaaaaaaaaaaaX" must try every way to split the a's between the inner + and outer + before giving up: 2^n attempts for n characters.
- DFA-based engines (RE2, Go's regexp, grep) never backtrack: they track all possible states simultaneously and run in linear time — at the cost of not supporting backreferences.
- Execution is capped: when the step budget is exhausted the run aborts with a clear message instead of freezing your tab.
- Runs 100% in your browser — nothing you paste leaves your device.