Replacement

Regular expression

/&(?:[a-zA-Z]+|#\d+|#x[0-9a-fA-F]+);/

Pattern breakdown

PartMeaning
Anchor or contextUse anchors when you need whole-string validation.
Main tokenThe core token sequence describes the accepted text shape.
Character classCharacter classes limit which characters are valid.
QuantifierQuantifiers control how many characters or groups are accepted.
FlagsUse language-specific flags such as i, m, or u only when needed.

Should match

  • Tom & Jerry
  • Tom&Jerry

Should not match

  • Tom & Jerry
  • not matching sample
  • Tom & Jerry invalid
  • Tom & JerryTom & Jerry

Test cases

InputExpectedWhy it matters
Tom & JerryMatchRepresentative valid input for this pattern.
Tom&JerryMatchRepresentative valid input for this pattern.
Tom & JerryNo matchCommon invalid or boundary input.
(empty string)No matchCommon invalid or boundary input.
not matching sampleNo matchCommon invalid or boundary input.
Tom & Jerry invalidNo matchCommon invalid or boundary input.
Tom & JerryTom & JerryNo matchCommon invalid or boundary input.

JavaScript

const re = /&(?:[a-zA-Z]+|#\d+|#x[0-9a-fA-F]+);/;
re.test(input);

Python

import re
bool(re.search(r"&(?:[a-zA-Z]+|#\d+|#x[0-9a-fA-F]+);", text))

PHP

$ok = preg_match('/&(?:[a-zA-Z]+|#\d+|#x[0-9a-fA-F]+);/', $value) === 1;

Java

Pattern pattern = Pattern.compile("&(?:[a-zA-Z]+|#\\d+|#x[0-9a-fA-F]+);");
pattern.matcher(value).find();

Go

re := regexp.MustCompile(`&(?:[a-zA-Z]+|#\d+|#x[0-9a-fA-F]+);`)
ok := re.MatchString(value)

Notes and production use

HTML Entity regex is useful as a practical starting point. Test it against your real input, avoid using it as the only security control, and prefer a parser when the format has complex grammar.

Performance tip: avoid running complex regular expressions repeatedly on very large untrusted strings without limits. Prefer anchored validation patterns, cap input length before matching, and use a parser when the target format has nested grammar.