๐Ÿ”‘ Password Strength Checker

Your password is never sent anywhere โ€” it is only evaluated locally in your browser.

Check how strong a password is based on its estimated entropy (how hard it is to guess) and an estimated brute-force crack time. Useful for confirming a new password is strong enough on the spot. Everything is processed only in your browser.

How to use

  1. Type the password you want to check into the input box.
  2. The entropy, estimated crack time, and strength level (Very Weak to Strong) update in real time.
  3. If the strength isn't high enough, add more character types or length and check again.

How the calculation works

This tool calculates a password's entropy โ€” how hard it is to guess, measured in bits. First it works out how many possibilities each character could be, from the character types present: 26 for lowercase, 26 for uppercase, 10 for digits and 32 for symbols, added together. Entropy is length ร— logโ‚‚(pool size). It then applies penalties: ร— 0.6 if a character repeats three or more times in a row, ร— 0.7 if the password starts with a run such as "1234" or "qwer", and a cap of 10 bits for passwords on a list of common ones. A common word with letters swapped for look-alike symbols or digits, or with numbers or symbols added before or after it (such as "P@ssw0rd" or "Password1!"), is capped at 24 bits. Crack time assumes an attacker making ten billion (10ยนโฐ) guesses a second, estimated as 2^entropy รท 10ยนโฐ seconds โ€” roughly the situation where a leaked password hash is brute-forced on powerful hardware.

Worked example

Eight random lowercase letters Entropy: 8 ร— logโ‚‚(26) โ‰ˆ 37.6 bits Estimated crack time: about 21 seconds Sixteen random lowercase letters give 16 ร— logโ‚‚(26) โ‰ˆ 75.2 bits, about 140,000 years. Twelve characters mixing upper and lower case, digits and symbols give about 78.7 bits, about 1.5 million years. Adding length does more than adding character types.

Things to be aware of

  • The estimate assumes the password was chosen at random. Combinations of words, names or dates are much easier to guess than the numbers suggest.
  • Even a strong password becomes a risk if reused: one breach exposes every account that shares it. Use a different password for each service.
  • A password manager combined with two-factor authentication is recommended.
  • Your password is processed in the browser and never sent anywhere.

FAQ

Is my password sent to a server?

No. All calculations happen entirely in your browser, and the password is never sent anywhere.

How is the "crack time" estimated?

It's based on the theoretical number of possible combinations given the password's character types (uppercase, lowercase, numbers, symbols) and length, assuming a brute-force attack. Actual attack methods can vary the real-world time.

Is it safe to type in a password I actually use?

Nothing leaves your browser, but as a precaution it's still a good habit to test with a placeholder string of the same length and character mix rather than a real password.

How do I make a stronger password?

Generally, combining uppercase, lowercase, numbers, and symbols, and using enough length (12+ characters is a common guideline), raises entropy and dramatically increases the estimated crack time.

Does it check resistance to dictionary attacks?

This tool estimates theoretical brute-force time based on character types and length โ€” it doesn't evaluate resistance to dictionary attacks using real words or common patterns. Avoid predictable words regardless of the score shown here.