Regex Tester & Debugger→Specialized Version
πŸ”

Password Regex Tester

Password Regex Tester

//gm
Flags:
Examples:
Str0ng!Passphrase weakpassword Sh0rt!aA NoDigits!Here
#MatchIndexGroups
1Str0ng!Passphrase0β€”

Password Regex Tester

Test and validate password patterns with this specialized regex tester. Includes tested patterns and real-time matching.

Recommended Password Pattern

``regex ^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)[a-zA-Z\d]{8,}$ `

Test Examples

Valid matches:

  • Password1
  • SecurePass123
  • MyP4ssword
Invalid (should not match):
  • password
  • PASSWORD1
  • Pass1
  • nouppercaseornumber

Pattern Explanation

Requires: 8+ characters, one lowercase, one uppercase, one digit

Alternative Patterns

1. ^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$

How to Use

1. The pattern above is preloadedβ€”or enter your own 2. Add test strings to validate 3. See real-time match highlights 4. Copy the pattern for your code

Regex Quick Reference

SymbolMeaningExample
\dAny digit\d{3} matches "123"
\wWord character\w+ matches "hello"
+One or morea+ matches "aaa"
*Zero or morea* matches "" or "aaa"
?Optionalcolou?r matches "color"
^Start of string^Hello
$End of stringworld$
[abc]Character class[aeiou] matches vowels
(ab)Alternation(catdog) matches either

The Pattern

`regex ^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{12,}$ `

Flags: gm β€” m makes ^ and $ match at each line break, so the pattern can be tested against a list.

Broken Down

PartWhat it does
(?=.*[a-z])lookahead: must contain a lowercase letter
(?=.*[A-Z])must contain an uppercase letter
(?=.*\d)must contain a digit
(?=.*[^\w\s])must contain a symbol
.{12,}$and be at least 12 characters

Tested Against Real Input

InputResult
Str0ng!Passphraseβœ… matches
weakpassword❌ no match
Sh0rt!aA❌ no match
NoDigits!Here❌ no match

The Important Caveat

Composition rules like these are mostly counterproductive β€” they push people to Password1! NIST SP 800-63B now recommends checking length and a breached-password list instead of mandating character classes.

Using It

`javascript const pattern = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{12,}$/gm;

// Test a single value β€” reset lastIndex first if the pattern is global pattern.lastIndex = 0; const isValid = pattern.test(value);

// Or find every match in a block of text const matches = [...text.matchAll(pattern)]; `

A global regex carries lastIndex between calls, so reusing one across test() calls returns alternating results. Either drop the g flag for validation or reset it each time.

Anchors, Greediness and Backtracking

Three behaviours account for most regex surprises, and this pattern shows all three.

Anchors. ^ and $ pin the match to the start and end of the input. Without them, \d{3} matches the 123 inside abc123def. With m in the flags β€” as here β€” they pin to each *line* instead, which is what lets one pattern be tested against a list.

Greediness. .* takes as much as it can and gives back only when forced; .*? takes as little as possible. On , the pattern <.*> matches the whole string and <.*?> matches just .

Backtracking. When a match fails, the engine reverses and tries other splits. Nested quantifiers like (a+)+ make that exponential, and a 30-character input can hang a server β€” a class of denial of service known as ReDoS. Avoid nesting quantifiers, and prefer explicit character classes over . wherever you can.

Testing It Properly

`javascript const pattern = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{12,}$/gm;

// A global regex keeps lastIndex between calls, so reusing one across // test() calls returns alternating true/false on the same input. pattern.lastIndex = 0;

// Named groups make the result readable const named = /(?\d{4})-(?\d{2})/; const { groups } = '2026-08'.match(named); `

Write the failing cases first. A pattern that accepts everything valid is easy; one that also rejects everything invalid is the hard half, and it is where the bugs are.

When Not to Use a Regex

Structured formats have parsers, and the parser is always more correct: new URL() for URLs, DOMParser for HTML, JSON.parse` for JSON, a date library for dates. Reach for a regex to *find* things in unstructured text, not to validate something a parser understands.

Frequently Asked Questions

Is this pattern secure enough?

For stronger security, add special characters: (?=.*[@$!%*?&]) and increase minimum length to 12+. Also consider checking against breached password lists.

What regex flavor does this use?

This tester uses JavaScript regex (ECMAScript). Most patterns work the same in Python, Java, and other languages.

Related Tools

Explore other tools you might find useful:

More Regex Tester & Debugger tools

You might also need