php-regex / regex-laravel
Laravel integration for PHPRegex: the Regex service and facade, and the regex:lint, regex:routes, regex:explain, regex:compare and regex:transpile commands.
Fund package maintenance!
Requires
- php: >=8.2
- illuminate/console: ^12.0
- illuminate/contracts: ^12.0
- illuminate/routing: ^12.0
- illuminate/support: ^12.0
- php-regex/regex-automata: ^2.0
- php-regex/regex-linter: ^2.0
- php-regex/regex-optimizer: ^2.0
- php-regex/regex-parser: ^2.0
- php-regex/regex-redos: ^2.0
- php-regex/regex-toolkit: ^2.0
- php-regex/regex-transpiler: ^2.0
- symfony/console: ^7.4|^8.0
Requires (Dev)
None
Suggests
- nikic/php-parser: To extract patterns with a full PHP parser.
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-05 22:22:04 UTC
README
PHPRegex Laravel
Laravel integration for PHPRegex: the Regex service and facade, and the regex:lint, regex:routes, regex:explain, regex:compare and regex:transpile commands.
Requires PHP 8.2+, Laravel 12.
Features
- A
Regexservice and aRegexfacade, registered by package discovery on install - Five artisan commands:
regex:lint,regex:routes,regex:explain,regex:compareandregex:transpile regex:lintreads your PHP files, your route constraints and your validator rules in one pass- Reports in console, JSON, GitHub, Checkstyle and JUnit formats, with clickable editor links
regex:lintjudges patterns for the PHP yourcomposer.jsonsupports, not for the one running it
Installation
composer require php-regex/regex-laravel
Package discovery registers PHPRegexServiceProvider and the Regex alias — nothing to
add to config/app.php. The config file is optional; publish it to edit defaults:
php artisan vendor:publish --tag=php-regex-config
Configuration
Every option lives in config/php-regex.php; unpublished keys take the package default, section by section.
| Option | Default | Role |
|---|---|---|
max_pattern_length, max_lookbehind_length |
100000, 255 |
Longest pattern string accepted; longest variable-length lookbehind |
runtime_pcre_validation |
false |
The Regex service also compiles each pattern with the running PHP |
php_version, pcre_version |
null |
PHP version and PCRE2 release regex:lint judges for ("8.2", "10.42") |
cache.store, cache.directory, cache.prefix |
null, '{storage_path}/framework/cache/php-regex', 'regex_' |
Cache for parsed patterns: a Laravel store, else this directory |
redos.enabled, redos.threshold, redos.ignored_patterns |
false, 'high', [] |
ReDoS analysis on or off, minimum severity reported (low to critical), patterns skipped |
analysis.warning_threshold |
50 |
Complexity score above which a warning is emitted |
automata.minimization_algorithm, automata.determinization_algorithm |
'hopcroft', 'subset-indexed' |
Algorithms behind regex:compare |
optimizations.* |
see the published file | Default optimization switches for regex:lint |
paths, exclude, ide |
['app'], ['vendor', 'node_modules', 'storage'], env('REGEX_PARSER_IDE', env('APP_EDITOR')) |
What regex:lint scans and skips, and the editor behind its clickable links |
Usage
use PHPRegex\Laravel\Facades\Regex; Regex::validate('/^[a-z0-9-]{3,}$/')->isValid; // true $invalid = Regex::validate('/^(unclosed/'); $invalid->error; // "Expected ) at end of input (found eof)" echo $invalid->caretSnippet; // Line 1: ^(unclosed // ^
Explain a pattern in plain English:
echo Regex::explain('/^\d{4}$/'); // Regex matches // Anchor: the beginning of a line // Character Type: A digit: [0-9] (exactly 4 times) // Anchor: the end of a line
Check one for ReDoS:
$analysis = Regex::redos('/^(a+)+$/'); $analysis->isSafe(); // false $analysis->severity->value; // 'critical' $analysis->getVulnerableSubpattern(); // 'a+' $analysis->headline(); // 'Exponential backtracking (proven)' $analysis->witness->render(); // '"a" x n . "!"', the input that triggers it
Or transpile it for another engine:
$result = Regex::transpile('/^[a-z]+(?=\d)$/i', 'javascript'); $result->constructor; // 'new RegExp("^[a-z]+(?=\\d)$", "i")'
The facade also exposes parse, parseTolerant, analyze, optimize, highlight, literals, generate and parsePattern.
Artisan commands
| Command | Description |
|---|---|
regex:lint |
Lint the regex patterns of your PHP code |
regex:compare |
Compare two patterns with automata |
regex:explain |
Explain a pattern in plain English |
regex:routes |
Detect route conflicts |
regex:transpile |
Translate a pattern for another regex engine |
php artisan regex:lint php artisan regex:lint app/ tests/ --format=json php artisan regex:routes --validate
Exit codes: 0 when nothing is wrong, 1 when the judged patterns or files have a problem, 2 when an option or the configuration cannot be used.
Documentation
- The Laravel guide — configuration, lint targets, the commands, upgrading from 1.x
- Quick start — first steps with the
Regexservice - The ReDoS guide — how the risk analysis reaches its verdicts
- Backward compatibility promise — what stays stable across releases
Resources
- Documentation
- The runtime library behind the facade: regex-toolkit
- Changelog
- Report issues and send pull requests in the main PHPRegex repository
Sponsors
If PHPRegex saves you time, consider sponsoring its maintenance.
License
MIT. See LICENSE.