PHPRegex

Static analysis, linter & logic solver for PHP regular expressions.

PHPRegex reads the regexes already living in your code — every preg_* pattern, every route constraint — and tells you what they really mean, whether they are safe, and how to make them shorter, faster, or provably equivalent.

composer require php-regex/php-regex:2.x-dev

New to regex? There is a ten-chapter tutorial.

PHP 8.2+ · PCRE2 10.49 · MIT — parsed, linted and proven against a corpus of 170+ real-world codebases: Laravel, Symfony, WordPress, PHPUnit…

regex analyze
$ vendor/bin/regex analyze '/^(?:a+)+$/'
PHPRegex 2.0.0-DEV by Younes ENNAJI

Runtime   : PHP 8.4.26
Command   : analyze
PCRE      : 10.49 2026-09-28
PCRE JIT  : 1
Backtrack : 1000000
Recursion : 100000

  [1/4] Parsing pattern
  Pattern
      → /^(?:a+)+$/
  Parse : OK

  [2/4] Validation
  Status : OK

  [3/4] ReDoS analysis
  Status     : Exponential backtracking (proven)
  Severity   : CRITICAL (score 10)
  Mode       : THEORETICAL
  Confidence : MEDIUM
  Attack: "a" x n . "!"
  Hotspot:   4-6

  [4/4] Explanation
Regex matches
  Anchor: the beginning of a line
  Start Quantified Group (one or more times)
    Non-capturing group
            'a' (one or more times)
    End group
  End Quantified Group
  Anchor: the end of a line

See the full walkthrough in the Quick Start.

One pipeline, every question

From a pattern literal to an answer, the same three stages every time — no regex is treated as an opaque string.

  1. Lexed

    The pattern literal is split from its flags and tokenized the way PCRE2 reads it.

  2. Parsed

    An immutable AST — twenty-nine node types, one per construct.

  3. Walked

    Visitors validate, explain, diagram, rewrite, or prove properties of the tree.

Railroad diagram drawn from a parsed pattern: start and end terminals joined by tracks through grouped branches and quantified loops
Drawn from the AST, not hand-drawn — diagram any pattern with the CLI.

Sixteen components, one language

Every analysis PHPRegex ships is a small library with one job — compose them, or use the toolkit.

Understand

Parser

The PCRE2 regex parser: lexer, immutable AST, a validator that answers as PHP's engine would.

Architecture →

Explain

Explains, highlights and draws regex ASTs — plain text, HTML, Mermaid, railroad diagrams.

Command examples →

Generator

Generates sample strings and test cases a regex matches or rejects.

Quick Start →

Prove

Automata

Compiles the regular subset of PCRE to automata: equivalence, intersection, subset, examples.

Logic solver →

Redos

Finds the patterns that backtrack catastrophically — with the exact input that proves it.

ReDoS guide →

Fix

Optimizer

Rewrites patterns into shorter equivalents and modernizes old syntax — equivalence provable, opt-in.

Lint rules →

Rector

Rewrites a preg_* call into the string function that does the same, only when the automata prove it.

Rector guide →

Transpiler

Transpiles PCRE patterns to JavaScript and Python, with the losses reported.

CLI overview →

Integrate

PHPStan

Reports the regex patterns your target PHP refuses — and, opt-in, lint, ReDoS and optimization findings.

PHPStan guide →

Psalm

Types $matches from the pattern, and reports the patterns your target PHP refuses.

Psalm guide →

LSP

Diagnostics, hovers, completions and code actions for the patterns of PHP files, in any LSP editor.

LSP guide →

Laravel

The Regex service and facade, with artisan lint, routes, explain, compare and transpile commands.

Laravel guide →

Symfony

The Regex service, with console lint, routes, security, analyze, compare and transpile commands.

Symfony guide →

CLI

Sixteen subcommands to parse, explain, validate, lint, hunt ReDoS, transpile and diagram — also a self-updating PHAR.

CLI guide →

Linter

Lints the regexes of a whole code base — validity, lint rules and ReDoS — with console, JSON and CI reports.

Lint your codebase →

Toolkit

One entry point to every analysis: parse, validate, explain, check ReDoS, optimize, generate, transpile and lint.

API reference →

Measured, not promised

Conformance

validate() verdicts measured against PHP's own PCRE2 on the official test suite.

Wire it into your stack

Three packages turn the analysis into findings where you already work. Until the 2.0.0 tag, the monorepo install covers all three — see the Quick Start.

PHPStan

Reports the regex patterns your target PHP refuses — lint, ReDoS and optimization findings on demand.

composer require --dev php-regex/regex-phpstan
includes:
    - vendor/php-regex/regex-phpstan/extension.neon
PHPStan guide →

Psalm

Types $matches from the pattern, and reports the patterns your target PHP refuses.

composer require --dev php-regex/regex-psalm
vendor/bin/psalm-plugin enable php-regex/regex-psalm
Psalm guide →

Rector

Rewrites a preg_* call into the string function that does the same, only when the automata prove it.

composer require --dev php-regex/regex-rector
// inside RectorConfig::configure()
->withSets([RegexSetList::STRING_FUNCTIONS]);
Rector guide →

Every framework and editor integration — Laravel, Symfony, the language server, the CLI — has its card on the guides index.