# safe-regex2

> detect possibly catastrophic, exponential-time regular expressions

Latest version **5.1.1** (published 2026-04-19) · MIT license · 0 weekly downloads

## Install

```sh
npm install safe-regex2
pnpm add safe-regex2
yarn add safe-regex2
bun add safe-regex2
```

Provides the command `safe-regex2`.

## Health

**Score 55/100 (C)** — status: active.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

## Facts

| | |
|---|---|
| Version | 5.1.1 |
| Published | 2026-04-19 |
| First published | 2019-02-18 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 11.2 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | James Halliday |
| Maintainers | zekth, eomm, gurgunday, ivan-tymoshenko, simoneb, climba03003, jsumners, fdawgs, metcoder95, matteo.collina |
| Keywords | catastrophic, exponential, regex, safe, sandbox |

## Links

- npm: https://www.npmjs.com/package/safe-regex2
- Repository: https://github.com/fastify/safe-regex2
- Issues: https://github.com/fastify/safe-regex2/issues
- Funding: https://github.com/sponsors/fastify
- npm.io page: https://npm.io/package/safe-regex2

## Dependencies (1)

- [ret](https://npm.io/package/ret.md) ~0.5.0

## Recent versions

- 5.1.1 (latest) — 2026-04-19
- 5.1.0 — 2026-03-12
- 5.0.0 — 2025-03-08
- 4.0.1 — 2024-12-30
- 4.0.0 — 2024-07-12
- 3.1.0 — 2022-12-04
- 3.0.0 — 2022-05-25
- 2.0.0 — 2019-02-18

## README

# safe-regex2

[![CI](https://github.com/fastify/safe-regex2/actions/workflows/ci.yml/badge.svg?branch=main)](https://github.com/fastify/safe-regex2/actions/workflows/ci.yml)
[![NPM version](https://img.shields.io/npm/v/safe-regex2.svg?style=flat)](https://www.npmjs.com/package/safe-regex2)
[![neostandard javascript style](https://img.shields.io/badge/code_style-neostandard-brightgreen?style=flat)](https://github.com/neostandard/neostandard)

Detect potentially [catastrophic](http://regular-expressions.mobi/catastrophic.html) [exponential-time](http://perlgeek.de/blog-en/perl-tips/in-search-of-an-exponetial-regexp.html)
regular expressions by limiting the [star height](https://en.wikipedia.org/wiki/Star_height) to 1.

This is a fork of https://github.com/substack/safe-regex at 1.1.0.

WARNING: This module has both false positives and false negatives.
It is not meant as a full checker, but it detects basic cases.

## Install
```sh
npm i safe-regex2
```

## Usage via npx

You can use this module via `npx` without installing it globally:

Example:
```sh
npx safe-regex2 '(x+x+)+y'
```

## Example

``` js
const safe = require('safe-regex2');
const regex = process.argv.slice(2).join(' ');
console.log(safe(regex));
```

```
$ node safe.js '(x+x+)+y'
false
$ node safe.js '(beep|boop)*'
true
$ node safe.js '(a+){10}'
false
$ node safe.js '\blocation\s*:[^:\n]+\b(Oakland|San Francisco)\b'
true
```

## Methods

``` js
const safe = require('safe-regex')
```

### const ok = safe(re, opts={})

Returns a boolean indicating whether the regex `re` is safe
and not possibly catastrophic.

`re` can be a `RegExp` object or just a string.

If `re` is a string and is an invalid regex, it returns `false`.

* `opts.limit` - maximum number of allowed repetitions in the entire regex.
Default: `25`.

## License

Licensed under [MIT](./LICENSE).

---
_Source: https://npm.io/package/safe-regex2 · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
