Password Strength Checker

Score a password's real entropy and crack time, with plain English reasons, on your device.

Input

Related tools

What it does

Estimates how many guesses a password would actually take, rather than counting its character classes. It looks for the things that make a long password cheap: entries from a bundled list of leaked passwords and common words, the same words spelled backwards or with digits swapped in for letters, walks across neighboring keys, runs like 1234 and wxyz, repeated chunks, and years and dates. Then it finds the cheapest way to build the whole password out of those pieces, converts that into a 0 to 4 score with a reason, and shows the crack time under five different attacks.

How to use it

Type or paste one password. The score, the estimated number of guesses, and the crack times update as you type. Read the pattern breakdown to see which parts of the password an attacker gets for free and which parts they have to guess character by character, then use the suggestions to fix the cheap parts. Switch the attack scenario to match the threat you care about: a rate limited login form and a stolen fast hash are separated by about twelve orders of magnitude.

Why this one

A password meter that counts symbols will tell you P@ssw0rd1 is strong, which is how people end up with passwords that fall in milliseconds. This one prices the patterns instead, and it tells you what it found rather than showing a colored bar. It also does the whole thing in the tab: your files and inputs never leave your device, nothing is stored, and there is deliberately no server endpoint, because a hosted password checker is a password collection service with extra steps.

FAQ
Is my password being sent anywhere?
No. The dictionaries ship with the page, the analysis runs in JavaScript inside your browser tab, and the password is never written to the URL, to storage, or to a network request. The page keeps working with the network off, which you can check yourself. This tool also has no curl endpoint, on purpose.
How does this compare to zxcvbn?
It borrows the idea: find the cheapest sequence of recognizable patterns that spells the password, price each one, and multiply. The differences are honest ones. The bundled dictionaries here hold about a thousand entries rather than tens of thousands, and the pattern costs are simpler. So treat the guess count as an order of magnitude, not a measurement, and treat a high score as the absence of the patterns it knows about rather than proof of strength.
Why does adding an exclamation mark and a capital barely change the score?
Because attackers already know that people put the capital first and the punctuation last. A cracking tool takes each dictionary word and applies those rules automatically, so Password1! costs a small multiple of password, not the enormous number a character-class calculator would report. Length and unpredictability are what actually move the number.
What should I do with a low score?
Use a password manager and let it generate the password, so it never has to be memorable. Where you do have to remember one, four or five unrelated words chosen at random beat a short scrambled string on both strength and typability. And do not reuse a password anywhere, since a strong password is worth nothing once the site that stored it is breached.

Keyboard shortcuts: press ? anywhere on this page to see them.