Common Regex Patterns for JavaScript (Copy-Ready Examples)
Every pattern here is compiled and matched against its own example by the toolkit, so a snippet cannot rot into a syntax error. Open one, load it into the tester, and adapt the bounds to your data.
- Treat each pattern as a starting point: tighten the quantifier bounds to your real data.
- Anchors decide whether you are validating or searching — check them before pasting.
- Copy the pattern into the tester and add your own failing example before you trust it.
This tool runs entirely in your browser. Your patterns and text are not uploaded, stored, or logged.
Patterns that are safe to ship
Email is the standard cautionary example: a pattern that accepts every valid address and rejects nothing invalid does not exist, because the specification is broader than any product needs. The useful question is not "is this regex correct?" but "which inputs do I intend to reject, and does this pattern reject exactly those?"
The patterns in this library are conservative and documented with their intent — an email pattern that follows the practical shape used in form validation, a URL pattern that handles scheme, host, path and query, a date pattern that distinguishes ISO from slash formats rather than accepting both and guessing later.
Reading a pattern library honestly
A snippet with no example is unverifiable. Each entry pairs the pattern with sample input, which means a broken entry is a failing test rather than a subtly wrong production behaviour. When you copy one out, keep the example next to it — that pair is the part that stays correct over time.
- Escaping inside a character class differs from escaping outside it; `[.` is literal, `\.` is escaped.
- `\d` matches ASCII digits only, so non-Latin numerals need `\p{Nd}` with the `u` flag.
- A pattern anchored with `^` and `$` behaves differently in multiline mode — check the flags.
Performance and catastrophic backtracking
Pattern libraries propagate ReDoS faster than any other class of bug, because a nested quantifier copied from a snippet runs against attacker-controlled input. If a pattern applies quantifiers to a group that itself contains a quantifier, test it against a long near-miss string before it reaches a request handler.
Frequently asked questions
Are these patterns tested?
Yes. Every entry is compiled and matched against its example in the test suite, so an entry that no longer compiles or no longer matches its sample fails the build rather than sitting on the page.
Which regex flavor do the patterns target?
ECMAScript, as implemented by Node.js and current browsers. Lookaheads, lookbehinds, named groups and unicode property escapes are supported; PCRE-only constructs are not used.
Why does an email pattern reject addresses I know are valid?
Because most email patterns trade specification coverage for predictability. Decide which inputs your product should reject and adjust the local-part and top-level-domain rules to that decision.