Password Strength Checker

Instant entropy analysis and realistic crack-time estimates — computed 100% in your browser. Nothing is sent, logged, or stored.

Enter a password

Analysis runs 100% in your browser — nothing is sent anywhere. Still, best practice: test a pattern, not your real password.

How the score works

Every password is scored on entropy — the mathematical measure of how unpredictable it is. The checker looks at two things: how large the character space is, and whether the password matches patterns attackers try first.

Very Weak — under 28 bits

Cracked instantly. Common words, short lengths, keyboard patterns.

Weak — 28–49 bits

Falls to a determined attacker in hours to days.

Fair — 50–69 bits

Acceptable for low-risk accounts. Replace for anything important.

Strong / Very Strong — 70+ bits

Infeasible to brute force offline. This is where you want to be.

What silently weakens a password

  • Dictionary words — cracking tools try millions of common words and word combinations before brute force.
  • Substitutions — @ for a and 0 for o are in every cracking rulebook. They add almost nothing.
  • Patterns — keyboard walks (qwerty), sequences (1234), and repeats (aaa) are checked in seconds.
  • Personal info — birthdays, team names, and pet names appear in targeted dictionaries built from social media.
  • Reuse — the strongest password becomes weak the moment the same one protects five accounts and one of them gets breached.

Failed the check? Generate a replacement in one click with the secure password generator or pick a memorable passphrase instead.

FAQ

Is it safe to type my real password here?

Technically yes — the analysis runs entirely in your browser with JavaScript, and no network request is made with your input. But the security-conscious habit is to test a similar pattern instead of your actual password, and that is what we recommend.

What does "entropy" mean for passwords?

Entropy measures unpredictability in bits. Each bit doubles the work an attacker must do. A random password gains entropy from length and character variety; a password based on a common word loses entropy because attackers try dictionary words first.

How is the crack time estimated?

We assume an offline attack at 10 billion guesses per second — a realistic figure for someone cracking a stolen password database with modern GPU hardware. Online attacks (typing into a login form) are far slower and rate-limited, so these numbers are the conservative case.