Skip to content
Limited Edition DevTools

Regex-LE

Find every regex in a codebase, and report which can be driven into catastrophic backtracking

FreeOpen sourceMITNo network access

No editor in the loop? npx -y regex-le-mcp runs the same engine as an MCP server, so an agent can call extract_patterns with nothing else installed, and cargo install regex-le puts the same check in a terminal. Every way to install it.

Regex-LE in use: Find every regex in a codebase, and report which can be driven into catastrophic backtracking

What Regex-LE does

A regular expression is easy to write and hard to trust. Regex-LE finds every pattern in the current file, runs one against the document to show real matches with line and column positions and capture groups, and screens each pattern for the shapes that cause catastrophic backtracking. Three commands: extract, test, validate.

What people use it for

Extract

List every regex pattern found in the document, literals and RegExp constructors alike.

Test

Run a found — or manually entered — pattern against the file and see matches with positions and named capture groups.

Validate

Check every pattern for syntax errors and screen it for ReDoS-prone shapes before it reaches production.

5 commands in the palette

Open the command palette and type the name. Nothing is bound to a shortcut by default — the editor's keymap is the user's, not ours.

Test Regexregex-le.test
Extract Patternsregex-le.extract
Validate Regexregex-le.validate
Open Settingsregex-le.openSettings
Help & Troubleshootingregex-le.help

Install Regex-LE

VS Code

ext install nolindnaidoo.regex-le

Open Quick Open (Cmd/Ctrl+P) and paste.

Cursor / VSCodium

cursor --install-extension OffensiveEdge.regex-le

VS Code forks pull from Open VSX, where the namespace is OffensiveEdge.

Zed

npx -y regex-le-mcp

Works in Zed today — add the command above as a custom MCP server from the agent panel, and extract_patterns appears in its tool list. There is no one-click listing in Zed's extension registry yet.

AI agents

npx -y regex-le-mcp

Runs Regex-LE's engine as an MCP server, so an agent can call extract_patterns with no editor involved. VS Code 1.101+ needs nothing — the extension registers it for you.

Where it ships

One engine, 6 places to get it. The ids differ by registry — copy the one for the editor you use.

Where Regex-LE lives

The other 15

Extract every string in a codebase, with its position, so a person can read them

Extract every hardcoded number in a codebase, so a person can check them

Extract every file path in a codebase, and say whether it still points at anything

Extract every color in a codebase, and say which ones are not in your palette

Extract every URL in a codebase, with its protocol and exact position

Extract every date and timestamp, and the exact instant each one resolves to

Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name

Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside

Extract every IP address, CIDR block and MAC, normalized and classified by scope

Check whether a page is scrapeable before the scraper is written, and say when it cannot tell

Find where one dependency is constrained differently across a repository's manifests

Identify the i18n library a project uses, then audit its catalogs by that library's rules

Find hardcoded credentials in a codebase, and never print one into the report

Compare the dotenv files in a tree, and say which keys are missing from which

Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts