How This Strength Checker Works
TL;DR: This tool estimates password strength using two signals:
entropy (computed as length × log₂(pool size)) and
pattern detection (sequences, repeats, dictionary words, common
compromised passwords). It then projects an offline crack time at 10 billion guesses/second.
Everything runs locally — your password never leaves the browser.
Understanding the Score
| Entropy | Label | Meaning |
|---|---|---|
| < 36 bits | Very Weak | Cracked in seconds to minutes |
| 36–59 bits | Weak | Hours to years offline — not enough |
| 60–79 bits | Moderate | Acceptable only with 2FA |
| 80–99 bits | Strong | Recommended minimum |
| 100+ bits | Very Strong | Resists any foreseeable attack |
P@ssw0rd! scores poorly despite "looking" complex, because the pattern is in every
attacker's dictionary. A random 16-character password scores far higher.
Common Weaknesses Detected
- Common compromised passwords — e.g. password, 123456, qwerty, P@ssw0rd
- Sequences — abc, 123, 987, keyboard walks (qwerty)
- Repeated characters — aaaa, 1111
- Single character class — only lowercase or only digits
- Short length — under 12 characters is risky
FAQ
How does this password strength checker work?
It calculates entropy via H = length × log₂(pool size), estimates offline crack time at
10 billion guesses/sec, and flags common weaknesses. Everything runs locally in your browser.
Is it safe to type my real password here?
Yes. The checker runs entirely in your browser — nothing is transmitted, logged, or stored. For extra caution you can test a variation, but technically nothing leaves your device.
What is a good password entropy score?
Aim for 80+ bits. 100+ bits resists any foreseeable offline attack.
Why does my complex password score low?
Substitutions like P@ssw0rd! are in attacker dictionaries. Entropy measures the
unpredictability of the method, not how the password looks.
Does this check against known breached passwords?
It flags the most common compromised passwords locally. For a full breach check, use haveibeenpwned.com — but never paste a real password into a third-party site.
Related guides: How Secure Is My Password? · Password Entropy Explained
We do not collect, store, or transmit any passwords.