Regex-LE
Find every regex in a codebase, and report which can be driven into catastrophic backtracking
No editor in the loop? npx -y regex-le-mcp runs the same engine as an MCP server, so an agent can call extract_patterns with nothing else installed, and cargo install regex-le puts the same check in a terminal. Every way to install it.

What Regex-LE does
A regular expression is easy to write and hard to trust. Regex-LE finds every pattern in the current file, runs one against the document to show real matches with line and column positions and capture groups, and screens each pattern for the shapes that cause catastrophic backtracking. Three commands: extract, test, validate.
What people use it for
Extract
List every regex pattern found in the document, literals and RegExp constructors alike.
Test
Run a found — or manually entered — pattern against the file and see matches with positions and named capture groups.
Validate
Check every pattern for syntax errors and screen it for ReDoS-prone shapes before it reaches production.
5 commands in the palette
Open the command palette and type the name. Nothing is bound to a shortcut by default — the editor's keymap is the user's, not ours.
regex-le.testregex-le.extractregex-le.validateregex-le.openSettingsregex-le.helpInstall Regex-LE
VS Code
ext install nolindnaidoo.regex-leOpen Quick Open (Cmd/Ctrl+P) and paste.
Cursor / VSCodium
cursor --install-extension OffensiveEdge.regex-leVS Code forks pull from Open VSX, where the namespace is OffensiveEdge.
Zed
npx -y regex-le-mcpWorks in Zed today — add the command above as a custom MCP server from the agent panel, and extract_patterns appears in its tool list. There is no one-click listing in Zed's extension registry yet.
AI agents
npx -y regex-le-mcpRuns Regex-LE's engine as an MCP server, so an agent can call extract_patterns with no editor involved. VS Code 1.101+ needs nothing — the extension registers it for you.
Where it ships
One engine, 6 places to get it. The ids differ by registry — copy the one for the editor you use.
Zed
built from Rust in the tool reporegex-leOpenno listing yet — this links Zed’s instructions for adding it by hand
Where Regex-LE lives
- VS Code Marketplaceregex-le
- Open VSXfor Cursor and VSCodium
- npmregex-le-mcp
- GitHubsource, issues, changelog
- MCP registryio.github.nolindnaidoo/regex-le
The other 15
Extract every string in a codebase, with its position, so a person can read them
Extract every hardcoded number in a codebase, so a person can check them
Extract every file path in a codebase, and say whether it still points at anything
Extract every color in a codebase, and say which ones are not in your palette
Extract every URL in a codebase, with its protocol and exact position
Extract every date and timestamp, and the exact instant each one resolves to
Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name
Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside
Extract every IP address, CIDR block and MAC, normalized and classified by scope
Check whether a page is scrapeable before the scraper is written, and say when it cannot tell
Find where one dependency is constrained differently across a repository's manifests
Identify the i18n library a project uses, then audit its catalogs by that library's rules
Find hardcoded credentials in a codebase, and never print one into the report
Compare the dotenv files in a tree, and say which keys are missing from which
Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts