PHPRegex Documentation
PHPRegex is a static analysis, linter & logic solver for PHP regular expressions. It parses every PCRE pattern into an AST and answers questions about it: validity ruled as PHP’s own engine would rule it, ReDoS safety with a proof or a witness, lint findings with fixes, provably equivalent rewrites, and pattern-to-pattern logic through automata.
It is written for the authors of PHP tools — static-analysis extensions, framework bundles, libraries that carry regexes. Start with your integration below. New to regex? The tutorial teaches regular expressions from scratch, and assumes nothing.
Start by task
I maintain a static-analysis tool or a library. The PHPStan, Psalm and Rector guides show what each extension reports and what it proves. Capture shapes derive what preg_match() writes into $matches straight from the AST, and the correctness contracts say, per feature, what is sound and what is heuristic.
I work on a Laravel or Symfony application. The Laravel and Symfony guides wire the Regex service and its commands; the CLI guide runs regex lint over the code base and in CI; the ReDoS guide reads the verdicts on the patterns your routes and validators accept.
I am new to regex. The tutorial is a ten-chapter walk from the first literal to the patterns running in production PHP.
Documentation map
Learn
- Quick Start - Install and a first analysis in a few runnable steps.
- Regex 101 tutorial - Ten chapters, from literals to real-world PHP.
- Regex in PHP - How PCRE behaves inside
preg_*.
Integrations
The guides index lists every integration on one page.
- PHPStan - The patterns your target PHP refuses, plus lint and ReDoS findings in static analysis.
- Psalm -
$matchestyped from the pattern, invalid patterns reported. - Rector -
preg_*calls rewritten into the string functions they provably equal. - Laravel - Service, facade, and artisan commands.
- Symfony - Bundle, service, and console commands.
- LSP - Diagnostics, hovers, completions and code actions in any editor.
- CLI - Sixteen subcommands, configuration, output formats, CI recipes.
- ReDoS guide - Verdicts, guarantees, confirmed mode, fixes.
- Cookbook - Practical patterns and examples.
- Troubleshooting - Common errors and how to fix them.
Concepts
- Key concepts - The fundamental ideas, explained for beginners.
- What is an AST? - The structured representation behind every analysis.
- Understanding Visitors - How operations run over the tree.
- ReDoS Deep Dive - Why patterns blow up and what is provable.
- PCRE vs Other Engines - Where PHP’s engine sits among the others.
Reference
- Reference index - The reference material on one page.
- Lint rules - Every diagnostic, rule and optimization.
- API - Entry points, return objects, exceptions.
- Diagnostics - Error types and messages.
- Diagnostics cheat sheet - Quick error reference.
- JSON output - Every key the
regexcommand prints in JSON. - Feature support matrix - PCRE construct coverage by component.
- Correctness contracts - Soundness and completeness guarantees by feature.
- Backward compatibility - What each release may change.
- Capture shapes - What
preg_match()writes into$matches. - Pattern info - The facts PCRE2 computes on every compiled pattern.
- Prefilters - When a cheap string function can answer before
preg_match(). - PCRE2 conformance - validate() verdicts measured against PHP’s engine.
- Sonar - Where each SonarPHP regex rule maps to a PHPRegex identifier.
- Logic solver - Pattern equivalence, intersection and subset via automata.
- FAQ and Glossary - Common terms and questions.
- External References - The sources behind the diagnostics.
Internals
- Architecture - Internal design.
- AST Traversal - How the tree is processed.
- Nodes Reference - AST node types.
- Visitors Reference - Built-in visitors and custom visitors.
- Extending Guide - How to add features or integrations.
- Maintainers Guide - Embedding PHPRegex in a tool as a first-class component.
How PHPRegex works in brief
PHPRegex treats a regex literal as structured input:
- The literal is split into pattern and flags.
- The lexer emits a token stream.
- The parser builds an AST.
- Visitors walk the AST to validate, explain, analyze, or transform.
Every example output in these docs was produced by PHPRegex itself, running the same PCRE2 engine it reasons about.
Tips for newcomers
- Always include delimiters and flags:
/pattern/flags(for example,/hello/i). - Build patterns step by step, then add constraints.
- Validate early:
vendor/bin/regex validatecatches errors quickly. - Explain patterns with
vendor/bin/regex explainwhen reviewing code.
Getting help
- Issues and bug reports: https://github.com/php-regex/php-regex/issues
- Real-world examples: https://github.com/php-regex/php-regex/tree/2.x/tests/Integration
- Interactive playground: https://regex101.com (PCRE2 mode) - good to explore what a pattern matches; the verdicts, proofs and ReDoS witnesses are the CLI’s job:
vendor/bin/regex analyze '/pattern/'.