Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →preg_match() can check whether a string fits a URL pattern you define, but a match does not prove that the string is universally valid, safe to fetch, or usable by another program. First decide what your application accepts: an absolute HTTP or HTTPS URL, another URI scheme, or a relative reference. Then validate that exact contract.
What should count as a valid URL?
“Valid” depends on what the application will do with the input. A link saved for display, a URL passed to cURL, and a destination fetched by your server have different requirements.
- Absolute HTTP(S) URL: require a scheme such as
https://and a host. - Any URI with a scheme: other schemes may be syntactically possible, but they may be inappropriate for a web link or unsafe for an application.
- Relative reference: values such as
/docs/pageor//example.com/pathdo not have the same form as an absolute URL. - Usable destination: syntax alone cannot establish that the host resolves, that the consumer accepts the input, or that fetching it is safe.
A regular expression tests only the grammar encoded in that expression. There is no single short pattern that should be described as implementing every URL or URI standard.
Use preg_match() for a narrow HTTP(S) contract
If your form accepts only absolute HTTP and HTTPS links with an ASCII hostname, an optional port, and an optional path, query, or fragment, a scoped pattern can be useful:
#1 Best Overall
<?php
$url = trim($input);
$pattern = '~Ahttps?://[A-Za-z0-9.-]+(?::[0-9]{1,5})?(?:[/?#][^s]*)?z~iD';
if (preg_match($pattern, $url) === 1) {
// The string matches this application's basic HTTP(S) shape.
} else {
// Reject or ask the user to correct the input.
}
This example is deliberately a basic shape check, not a standards-compliant URL parser. It requires http:// or https://, requires a hostname-shaped string, permits a numeric port from one to five digits, and allows a path, query, or fragment. It does not establish that the port is in range, that hostname labels are valid, that the host exists, or that a destination is safe. It also excludes internationalized hostnames in their Unicode form and does not accept relative references.
Adjust the pattern only after writing down the forms the application actually needs. If users may enter internationalized domain names, decide how your application will normalize them rather than assuming an ASCII-only expression is sufficient.
Rank #2
When to use PHP’s URL filter or a parser
PHP provides FILTER_VALIDATE_URL through filter_var(), and parse_url() can split a URL into components. They serve different purposes and should not be treated as interchangeable safety checks.
| Approach | Useful for | Important limitation |
|---|---|---|
preg_match() |
Checking a clearly defined application-specific pattern, such as requiring an absolute HTTP(S) form. | It enforces only the grammar you wrote; a match does not prove universal validity or destination safety. |
FILTER_VALIDATE_URL |
A built-in format check for URL strings. | The PHP manual describes it as based on RFC 2396, calls that basis obsolete, says the filter is ASCII-only, and warns that a further protocol check may be needed. Passing does not imply a safe or permitted scheme. |
parse_url() |
Extracting components such as scheme, host, and path for subsequent checks. | Parsing components is not itself validation or a security policy; PHP documents its parsing basis as RFC 3986. |
The PHP manual’s validation filters documentation says the URL filter “only works on ASCII” URLs, so internationalized domain names in Unicode form are rejected. It also warns that a URL may be considered valid without specifying the HTTP protocol, meaning an application expecting HTTP or HTTPS must check the scheme separately.
The filter_var() manual calls the filter’s RFC 2396 basis obsolete and notes that parse_url() uses RFC 3986. RFC 3986 is the IETF generic URI syntax standard, published in January 2005: RFC 3986. PHP’s documentation also shows that the filter can accept unusual schemes and loopback addresses; it is not an allowlist.
Check compatibility with the software that consumes the URL
A string that passes one check may still be rejected or interpreted differently by the next component. PHP’s URL parsing RFC notes that strings accepted by FILTER_VALIDATE_URL may not be accepted by cURL, whose URL parsing is based on RFC 3986. Validate against the PHP version and the downstream client your application actually uses.
Rank #4
Input forms also vary: the PHP manual’s behavior does not make FILTER_VALIDATE_URL a check for relative references, and a PHP bug report documents rejection of scheme-relative references such as //google.com/. If relative or scheme-relative input is part of your contract, handle it explicitly rather than treating it as an absolute URL.
Keep URL syntax checks separate from fetch safety
If your application only stores or displays a link, a syntax and scheme policy may be enough for that feature. If your server fetches a user-provided URL, a successful regex or filter check is not a security boundary. Define separate controls for permitted schemes, hosts and resolved addresses, and how redirects are handled. In particular, allowing only a familiar-looking hostname string does not establish where it resolves or where a redirect will lead.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Choose the validation method in this order: define accepted input forms, enforce the required scheme and host policy, and then confirm that the parser or network client consuming the URL accepts the same input. Treat format validation and destination authorization as separate decisions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

