Password Regex Tester
Test and validate password patterns with this specialized regex tester. Includes tested patterns and real-time matching.
Recommended Password Pattern
``regex
^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)[a-zA-Z\d]{8,}$
`
Test Examples
Valid matches:
- Password1
SecurePass123MyP4ssword
Invalid (should not match):
passwordPASSWORD1Pass1nouppercaseornumber
Pattern Explanation
Requires: 8+ characters, one lowercase, one uppercase, one digit
Alternative Patterns
1. ^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$
How to Use
1. The pattern above is preloadedβor enter your own
2. Add test strings to validate
3. See real-time match highlights
4. Copy the pattern for your code
Regex Quick Reference
| Symbol | Meaning | Example | ||
|---|---|---|---|---|
| \d | Any digit | \d{3} matches "123" | ||
| \w | Word character | \w+ matches "hello" | ||
| + | One or more | a+ matches "aaa" | ||
| * | Zero or more | a* matches "" or "aaa" | ||
| ? | Optional | colou?r matches "color" | ||
| ^ | Start of string | ^Hello | ||
| $ | End of string | world$ | ||
| [abc] | Character class | [aeiou] matches vowels | ||
| (a | b) | Alternation | (cat | dog) matches either |
The Pattern
`regex
^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{12,}$
`
Flags: gm β m makes ^ and $ match at each line break, so the pattern can be tested against a list.
Broken Down
| Part | What it does |
|---|---|
(?=.*[a-z]) | lookahead: must contain a lowercase letter |
(?=.*[A-Z]) | must contain an uppercase letter |
(?=.*\d) | must contain a digit |
(?=.*[^\w\s]) | must contain a symbol |
.{12,}$ | and be at least 12 characters |
Tested Against Real Input
| Input | Result |
|---|---|
Str0ng!Passphrase | β matches |
weakpassword | β no match |
Sh0rt!aA | β no match |
NoDigits!Here | β no match |
The Important Caveat
Composition rules like these are mostly counterproductive β they push people to Password1! NIST SP 800-63B now recommends checking length and a breached-password list instead of mandating character classes.
Using It
`javascript
const pattern = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{12,}$/gm;
// Test a single value β reset lastIndex first if the pattern is global
pattern.lastIndex = 0;
const isValid = pattern.test(value);
// Or find every match in a block of text
const matches = [...text.matchAll(pattern)];
`
A global regex carries lastIndex between calls, so reusing one across test() calls
returns alternating results. Either drop the g flag for validation or reset it each time.
Anchors, Greediness and Backtracking
Three behaviours account for most regex surprises, and this pattern shows all three.
Anchors. ^ and $ pin the match to the start and end of the input. Without them,
\d{3} matches the 123 inside abc123def. With m in the flags β as here β they
pin to each *line* instead, which is what lets one pattern be tested against a list.
Greediness. .* takes as much as it can and gives back only when forced; .*? takes
as little as possible. On , the pattern <.*> matches the whole string and
<.*?> matches just .
Testing It Properly
`javascript
const pattern = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{12,}$/gm;