Password Strength Checker

Type any password to see its real entropy, estimated crack time, and weakness flags. Everything is calculated locally — your password never leaves your browser.

100% Client-side Nothing transmitted No tracking

Password strength checker

Strength: – Entropy: – Crack time: –
Type a password above to test it.

How This Strength Checker Works

TL;DR: This tool estimates password strength using two signals: entropy (computed as length × log₂(pool size)) and pattern detection (sequences, repeats, dictionary words, common compromised passwords). It then projects an offline crack time at 10 billion guesses/second. Everything runs locally — your password never leaves the browser.

Understanding the Score

Password strength score guide
EntropyLabelMeaning
< 36 bitsVery WeakCracked in seconds to minutes
36–59 bitsWeakHours to years offline — not enough
60–79 bitsModerateAcceptable only with 2FA
80–99 bitsStrongRecommended minimum
100+ bitsVery StrongResists any foreseeable attack
Important: Entropy measures the generation method, not how a password looks. P@ssw0rd! scores poorly despite "looking" complex, because the pattern is in every attacker's dictionary. A random 16-character password scores far higher.

Common Weaknesses Detected

FAQ

How does this password strength checker work?

It calculates entropy via H = length × log₂(pool size), estimates offline crack time at 10 billion guesses/sec, and flags common weaknesses. Everything runs locally in your browser.

Is it safe to type my real password here?

Yes. The checker runs entirely in your browser — nothing is transmitted, logged, or stored. For extra caution you can test a variation, but technically nothing leaves your device.

What is a good password entropy score?

Aim for 80+ bits. 100+ bits resists any foreseeable offline attack.

Why does my complex password score low?

Substitutions like P@ssw0rd! are in attacker dictionaries. Entropy measures the unpredictability of the method, not how the password looks.

Does this check against known breached passwords?

It flags the most common compromised passwords locally. For a full breach check, use haveibeenpwned.com — but never paste a real password into a third-party site.

Ready for a strong one? Generate a secure password.

Related guides: How Secure Is My Password? · Password Entropy Explained

We do not collect, store, or transmit any passwords.