What does « testing a regular expression » mean?
Testing a regular expression (« regex test online », « test regex javascript ») means running a pattern against real text and observing exactly what the engine returns: the matching strings, their position, and the value of the capture groups. A pattern that « looks right » says nothing until it has run on your data — that is the only gap that counts between the tutorial regex and the production regex.
The test answers three distinct questions. Does it match : the matches table tells you on the first line. Where and how much : the index and length show whether the anchor was in the right place. What does it capture : the numbered or named groups reveal whether the part you meant to extract really is that part.
The metacharacters that make all the difference
The dot . matches any character except a newline — hence the flag s when your text is multiline. The quantifiers *, + and ? are greedy : they stop at the first sufficient number of repetitions. The suffix ? (*?, +?, {2,5}?) reverses this behavior and gives the lazy version, which you should almost always prefer when a .* eats the end of the line.
Brackets define a class: [abc] accepts one of the listed characters, [^abc] anything but them, [a-z0-9] a range. Beware of the negation at the start of a class — [^...] only for the first position, otherwise ^ becomes literal again. The pipe | separates alternatives and behaves like low precedence: ^cat|dog$ means « the whole text is cat » or « the whole text is dog », not « cat or dog at the start or the end » — you need to group instead: ^(?:cat|dog)$.
Groups, lookahead and lookbehind
Parentheses capture. Group 1 is accessible with $1 on the replacement side and \1 on the pattern side, named groups with $<nom> and \k<nom> — far more readable once you have three groups. (?:...) groups without creating a number, which you should prefer as soon as you capture only for the structure.
Lookarounds (lookaround) check without consuming: (?=...) requires what follows to match, (?!...) forbids it, (?<=...) and (?<!...) do the same for what precedes. This is how you require a special character in a password without including it in the capture: ^(?=.*\d)(?=.*[A-Z]).{12,}$.
ReDoS: when a regex becomes a time bomb
The ReDoS (Regular Expression Denial of Service) comes from backtracking : faced with an almost-matching input, a pattern like (a+)+$ explores every way of splitting the « a » characters before failing, and the number of explosions grows exponentially. Two habits: test the pattern on a realistic volume — the Performance tab does it for you — and never run an unauditable regex on external input with no size limit. On a server, a hanging regex freezes an entire worker until the timeout expires.
JavaScript, PCRE, Python: the same basics, a few differences
The tester uses the browser's native engine, i.e. ECMAScript. The core syntaxes — classes, quantifiers, groups, lookahead, flags g i m s u y — are shared with PCRE (PHP, Perl), with Python via re, with Java and Go. The differences mostly concern lookbehind (long missing from JavaScript, now supported), Unicode properties, and inline flags like (?i), which are PCRE-specific. Translating a pattern from one language to another is therefore a matter of detail — not invention.
Recommended for
Front-end and back-end developers (form validation, log parsing, data migration), ops and DevOps (configuration filters, WAF rules), QA testers and analysts (column extraction, format checking), writers and data analysts (file cleaning), students (understanding metacharacters), and anyone who needs a regular expression tester fast, complete and private — complemented by the JSON formatter, theURL encoder decoder, theBase64 encoder decoder and the JWT encoder decoder.