Regex Escape

Escape text so a regex matches it literally.

Input
TEXT input
Output
Result

About this tool


Around a dozen characters have special meaning in a regular expression. Escaping them with backslashes turns the text into a pattern that matches those characters literally, which is what you need when building a pattern from a string rather than writing one by hand.

The security reason to do this matters more than the convenience. Interpolating unescaped user input into a regex lets that input change the pattern's meaning, and a crafted value can produce a pattern that takes exponential time to run, a denial of service through a search box.

How to use it

  1. Paste or upload your textDrop a file onto the input pane, use the file picker, or paste the text directly.
  2. Adjust the options if neededThe defaults suit most input; open Options to change the behaviour.
  3. EscapePress Escape, or use Ctrl+Enter (Cmd+Enter on macOS).
  4. Copy or downloadCopy the result, or download it as a .txt file.

Worked examples


Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.

A version string used as a pattern

Input

v1.2.3 (build+42)

Output

v1\.2\.3 \(build\+42\)

Without escaping, the dots would match any character and the parentheses would create capture groups.

What to watch for


The details that decide whether a conversion is correct, and where information can be lost without any error being raised.

Which characters are escaped
The metacharacters . * + ? ^ $ { } ( ) | [ ] \ and / all get a backslash. Each would otherwise change the pattern: a dot matches any character, a plus repeats, parentheses group, and brackets open a character class. The forward slash is escaped so the result is also safe inside a /.../ literal.
Why interpolation is risky
If a user searches for "a.b" and you build a regex from it directly, the dot matches any character, so "axb" matches too. Worse, input like (a+)+ creates a pattern that backtracks exponentially and can hang the process. Escaping first removes both problems.
Doing this in code
JavaScript has no built-in escape function, a RegExp.escape proposal exists but is not yet widely available. The standard approach is str.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"). This tool applies the same transformation so you can verify a specific string.

Limitations


  • Escapes for JavaScript regex syntax; other flavours differ slightly in which characters need escaping.
  • Processing happens in your browser, so very large inputs are bounded by available memory. Files above roughly 10 MB are handled but will feel slower, and multi-hundred-megabyte files are better suited to a command-line tool.

Questions


When do I need this?
Whenever a literal string becomes part of a pattern, a search term, a filename, a version number. Anything not written as a regex by hand should be escaped.
Why is the forward slash escaped?
So the result can be dropped inside a /.../ literal without terminating it early. The escape is harmless in other contexts.