Password Strength Checker
Measure how many guesses a password would actually take — not whether it has a capital letter.
Runs entirely in your browser
Loading tool...
How to use
- Type or paste a password. Nothing leaves the page.
- Read the entropy — the number of guesses, expressed in bits.
- Check the warnings: they explain what makes a password cheaper to guess than its length suggests.
- Aim for length over punctuation. A long passphrase beats a short complicated one.
Features
- Entropy in bits, not a rule checklist that P@ssw0rd1 would pass.
- An offline crack-time estimate at 10 billion guesses a second.
- Detects common passwords, repeats, sequences, keyboard runs and years.
- Recognises that a common word with digits appended is still a common word.
- Never sent and never stored — measured entirely in your browser.
Frequently asked questions
- Is my password sent anywhere?
- No. Everything is measured in the page, and nothing is stored, logged or transmitted. That is not a nicety — a strength checker that uploaded passwords would be a way of collecting them.
- Why does P@ssw0rd score so badly when it has everything?
- Because it is on every attacker's list. Rules about capitals, digits and symbols measure how a password looks, not how hard it is to guess, and the substitutions people make to satisfy those rules — a for @, o for 0 — are the first ones any cracking tool tries. It costs an attacker a lookup, not a search.
- What is a bit of entropy?
- Each bit doubles the number of guesses required. 40 bits is about a trillion possibilities — hours for a determined attacker. 80 bits is beyond reach today. Adding a character to a password is worth more than adding a symbol to a short one, which is why length is the advice.
- How realistic is the crack time?
- It is deliberately pessimistic: 10 billion guesses a second is an offline attack against a fast hash on commodity hardware. A site storing passwords properly, with a slow salted algorithm, would be many orders of magnitude slower — but your password should not depend on that site having done its job.
Related tools
Generate strong random passwords.
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.
Generate random UUIDs one at a time or in bulk.