> why not just wrap vanilla JS regex, rejecting patterns including them?
Yea! I was thinking about this too actually. And this would solve the problem of being server side only. I'm thinking about making a new version to do just this.
For a pattern rejecting wrapper, how would you want it to communicate that an unsafe pattern has been created.