Skip to content
Toolbench

Password Strength Checker

Measure how many guesses a password would actually take — not whether it has a capital letter.

Runs entirely in your browser

Loading tool...

How to use

  1. Type or paste a password. Nothing leaves the page.
  2. Read the entropy — the number of guesses, expressed in bits.
  3. Check the warnings: they explain what makes a password cheaper to guess than its length suggests.
  4. Aim for length over punctuation. A long passphrase beats a short complicated one.

Features

  • Entropy in bits, not a rule checklist that P@ssw0rd1 would pass.
  • An offline crack-time estimate at 10 billion guesses a second.
  • Detects common passwords, repeats, sequences, keyboard runs and years.
  • Recognises that a common word with digits appended is still a common word.
  • Never sent and never stored — measured entirely in your browser.

Frequently asked questions

Is my password sent anywhere?
No. Everything is measured in the page, and nothing is stored, logged or transmitted. That is not a nicety — a strength checker that uploaded passwords would be a way of collecting them.
Why does P@ssw0rd score so badly when it has everything?
Because it is on every attacker's list. Rules about capitals, digits and symbols measure how a password looks, not how hard it is to guess, and the substitutions people make to satisfy those rules — a for @, o for 0 — are the first ones any cracking tool tries. It costs an attacker a lookup, not a search.
What is a bit of entropy?
Each bit doubles the number of guesses required. 40 bits is about a trillion possibilities — hours for a determined attacker. 80 bits is beyond reach today. Adding a character to a password is worth more than adding a symbol to a short one, which is why length is the advice.
How realistic is the crack time?
It is deliberately pessimistic: 10 billion guesses a second is an offline attack against a fast hash on commodity hardware. A site storing passwords properly, with a slow salted algorithm, would be many orders of magnitude slower — but your password should not depend on that site having done its job.

Generate strong random passwords.

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.

Generate random UUIDs one at a time or in bulk.

Password Strength Checker — Entropy and Crack Time