Skip to content
Tool4SaaS
HomeAboutContactBlog
Tool4SaaS

185 fast, local utilities for developers and creators. No sign-ups — most tools run in your browser (see /privacy).

hello@tool4saas.com

Categories

  • Text & Documents

  • Business & Writing

  • Developer Tools

  • Converters

  • Generators

  • Images & Design

  • PDF Tools

  • Calculators

  • Finance & Money

  • Health & Fitness

  • SEO & Marketing

  • Time & Date

Popular Tools

  • Invoice Generator

  • QR Code Generator

  • Word Counter

  • Password Generator

  • JSON Formatter

  • Mortgage Calculator

  • EMI Calculator

  • SIP Calculator

  • View all tools →

Company

  • All Tools

  • About Us

  • Author

  • Methodology

  • Blog

  • Contact Us

Guides

  • Invoice Generator Guide

  • QR Code Generator Guide

  • Resume Builder Guide

  • Mortgage Calculator Guide

  • Password Generator Guide

  • Word Counter Guide

  • llms.txt (for AI)

© 2026 Tool4SaaS. All rights reserved.

  • Privacy Policy

  • ·
  • Terms of Service

  • ·
  • ·
  1. Home
  2. /
  3. Blog
  4. /
  5. Developer Guide
  6. /
  7. Regex Flags and Capture Groups That Work

Regex Flags and Capture Groups That Work

Regex g/i/m/s flags with examples, named vs numbered groups, backreferences + catastrophic-pattern defense in isolated workers. Free tester.

By Tool4SaaS Editorial Team · Published 2026-10-07 · Updated 2026-10-07 · 3 min read

Try it now — Regex Tester, free in your browser

Test JavaScript regular expressions · No signup · No watermark · Free forever.

Open Regex Tester →
On this page
  • g/i/m/s flags
  • Capture groups
  • Catastrophic defense

Log file, 4,000 lines, one task: pull every 2024-05-01-style date plus the order number on the same line. My first pattern .*date.* matched the whole file as one blob. My second, with the right flags and a named group, returned 37 clean rows in one pass. Two thirds of regex pain is flags, not patterns — g/i/m/s change what the same characters mean. This guide teaches flags first, capture groups second, and the catastrophic patterns that freeze tabs.

Part of the developer toolkit guide. Test live in the regex tester (worker-isolated, per-flag control). Validate JSON logs with the JSON formatter first.

Flags g/i/m/s: same pattern, four meanings

FlagDoesExample win
g (global)All matches, not just first\d+ pulls every number (“Order 42” → 42, plus the rest)
i (insensitive)Case-blinderror matches ERROR, Error, eRrOr in logs
m (multiline)^/$ per line4000-line logs: match per-line timestamps
s (dotAll). crosses newlinesMulti-line stack traces as one match

Debug sequence for a dead pattern: toggle g (only-first vs all?), then i (case?), then m (anchors per line?). Nine of ten “broken regex” reports I review are a missing flag, not a wrong pattern.

Capture groups: named beats numbered

(\d{4})-(\d{2})-(\d{2}) captures year/month/day as groups 1/2/3 — until someone adds a group in front and every index shifts. Named groups ((?<year>\d{4})-(?<month>\d{2})) survive refactoring because names don't renumber. Non-capturing (?:…) groups without capturing (keeps indexes stable, slight speed win). Backreferences (\1) match repeats — (\w+) \1 finds doubled words like “the the”. Practice set: extract order + date pairs from the sample log in the tester with one pattern and two named groups.

Catastrophic patterns (and the worker that saves you)

(a+)+$ on a long non-matching string doesn't fail — it explodes, trying exponentially many paths (ReDoS). Nested quantifiers, overlapping alternations and greedy .* before a required suffix are the classic triggers. Defenses in order: prefer lazy quantifiers or explicit character classes, anchor patterns, cap input size — and test in a runner that isolates execution. Our tester runs patterns in a Web Worker with timeouts and flags potentially-catastrophic shapes before running, so the worst case is a warning, never a frozen tab. If your pattern needs a paragraph of explanation, split it into two patterns and a line of code instead.

General guidance only. For security-critical validation (emails, URLs, auth), prefer purpose-built parsers plus allowlists — regex alone under-validates.

Related free tools

JSON Formatter →Find & Replace →

Frequently asked questions

g finds all matches rather than first, i ignores case so error matches ERROR, m anchors ^/$ per line for 4000-line timestamps, and s lets dot cross newlines for stack traces. Most dead patterns miss a flag rather than the pattern itself. Debug by toggling g, then i, then m in sequence.

Named groups like (?<year>...) survive refactoring since names don't renumber, while numbered groups shift when additions arrive in front. Non-capturing (?:...) groups without capturing to keep indexes stable with slight speed wins. Backreferences like \1 match repeats, finding doubled words such as the the reliably.

Catastrophic backtracking from nested quantifiers like (a+)+$ explodes exponentially on non-matches rather than failing. Overlapping alternations and greedy .* before required suffixes trigger ReDoS similarly. Use lazy quantifiers, explicit classes and anchors, cap input size, and test in worker-isolated runners with timeouts for safe pattern development workflows.

Multiline flag m for per-line anchors, g for all matches, and named groups for order and date fields. Test against a real 4000-line log sample rather than one line, since .*date.* alone matches the whole file as one blob. One pattern with two named groups returned 37 clean rows in one pass.

For security-critical input like emails, URLs and auth, prefer purpose-built parsers plus allowlists. Regex alone under-validates edge cases attackers love and needs paragraphs of explanation for complex rules. If a pattern grows unwieldy, split it into two patterns plus a line of code instead for dependable production validation.

Done reading — open the Regex Tester

Test JavaScript regular expressions — free in your browser, no signup.

Open Regex Tester →

Keep reading in this guide

Pillar guide

Debug API Responses Locally: JSON, Base64, JWT, Regex Guide

In this silo

Why JSON.parse Fails: Trailing Commas and Quotes

In this silo

Base64 URL-Safe vs Standard: Padding and Modes

In this silo

Check JWT Expiry Without Trusting the Token