import re
regex = re.compile(r"(<.+?)(?<=\s)on[a-z]+\s*=\s*(?:(['\"])(?!\2).+?\2|(?:\S+?\(.*?\)(?=[\s>])))(.*?>)", flags=re.IGNORECASE)
test_str = ("<meta name=\"keywords\" content=\"keyword1, keyword2, keyword3\">\n"
"<a href=\"something\" onclick= \"bad()\">text</a> onclick not in tags\n"
"<a href=\"something\" onclick =bad()>text</a>\n"
"<a href=\"something\" onclick=bad('test')>text</a>\n"
"<a href=\"something\" onclick=bad(\"test\")>text</a>\n"
"<a href=\"something\" onclick=\"bad()\" >text</a>\n"
"<a href=\"http://mydomain.com/index.php?oninaval=12\" class=\"titi\">text</a>\n"
"What if I write john+onelia=love forever?\n\n"
" <a href=\"something\" onclick=\"bad()\">text</a> onclick not in tags \n"
" <a href=\"something\" onclick=bad()>text</a>\n"
" <a href=\"something\" onclick=\"bad()\" >text</a>\n\n"
"<a href=\"something\" onclick=a++ >text</a>\n\n"
"onclick=\"asd <span class=\"myclass\"> not in tag too.</span>\n"
"<!-- onclick=\" --><a href=\"something\" onclick= \"bad()\">text</a>\n"
"<textarea><enter onclick=\"dothat()\" text here></textarea>\n"
"yoko ono=\"john lennon\"\n"
"<img src=\"/images/img1.jpg\" alt=\"onclick=thegood() onclick=thebad() \"/>\n"
"<img alt=\"onclick=\" src=/images/theugly.jpg> the most important part of the message <p class=\"disappears\"></p>\n\n"
"<a href=\"\" onmouseover=a=7>button1</a>\n"
"<a href=\"something\" onclick=a++>text</a>\n"
"<a href=\"something\" onclick=a<<1>text</a>\n"
"<a href=\"\" onmouseover=\"alert(a);\">button2</a>")
matches = regex.finditer(test_str)
for match_num, match in enumerate(matches, start=1):
print(f"Match {match_num} was found at {match.start()}-{match.end()}: {match.group()}")
for group_num, group in enumerate(match.groups(), start=1):
print(f"Group {group_num} found at {match.start(group_num)}-{match.end(group_num)}: {group}")
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Python, please visit: https://docs.python.org/3/library/re.html