/

Password Strength Checker

Processed Client Side

Analyze password entropy, estimate crack time, and get concrete tips to make it stronger. Everything runs in your browser — nothing is sent anywhere.

Password
The password never leaves this page. Analysis is based on entropy and common-pattern heuristics — treat it as guidance, not a guarantee.
Analysis
Enter a password to see its strength.

Bookmark this tool now — skip the search next time you need it.

About Password Strength Checker

This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.

Measure how strong a password actually is, using entropy rather than the arbitrary rules most sites enforce. It reports the size of the character pool, the length, the resulting entropy in bits, and an estimated time to crack, alongside a checklist of the criteria the password meets. The distinction that matters is between rules and entropy: "P@ssw0rd1" satisfies almost every complexity rule ever written and is genuinely terrible, because the substitutions are the first thing any cracking tool tries. Entropy measures the actual search space, which is the number that determines how long a real attack takes.

Key features

  • Entropy calculated in bits from the character pool and length
  • Estimated crack time expressed in human terms
  • Character pool size and length reported separately, so you can see which one is limiting you
  • Criteria checklist covering length, uppercase, lowercase, digits, and symbols
  • Common-password detection, which drops the rating regardless of what the rules say
  • Five strength bands from Very Weak to Very Strong
  • Show and hide toggle for the password field
  • Runs entirely in your browser — nothing is transmitted, logged, or stored

How to use it

  1. Type or paste the password into the field.
  2. Read the entropy figure and the estimated crack time.
  3. Check which criteria it fails.
  4. Lengthen it — that raises entropy faster than adding another symbol.

Tips & common mistakes

  • Entropy is the number that matters. Aim for 75 bits or more on anything important; below about 50 bits is within reach of a determined offline attack.
  • Length beats complexity. Adding four characters raises entropy far more than swapping an a for an @, and the substitution tricks are in every cracking dictionary already.
  • Crack-time estimates assume an offline attack against a leaked hash. An online login with rate limiting is much slower to attack — but you should assume the hash will leak.
  • A password matching a known common password is rated very weak no matter how many rules it passes, because attackers start from those lists.
  • Four random unrelated words make a strong and memorable passphrase. A quote or a song lyric does not, because it is guessable text rather than random choice.
  • Nothing you type here is transmitted or stored — it is all in-browser. Even so, prefer testing a pattern similar to your real password rather than the live one.
  • The real fix is a password manager generating a unique password per site. Strength on a reused password is undone the moment any one site is breached.
  • Need a strong password rather than just a rating for an existing one? Generate one with the Password Generator.

Related tools

Browse all 8 Security tools

Frequently asked questions

10

No. The entire analysis runs in your browser using JavaScript. The password is never transmitted, logged, or stored — you can even disconnect from the internet and it still works.

Strength is based on entropy — the character pool size raised to the password length, expressed in bits. The tool also checks against common passwords and detects repeated characters and sequential or keyboard patterns.

Aim for at least 60 bits for everyday accounts and 80 bits or more for important ones like email or banking. Longer passwords raise entropy faster than adding symbols.

It assumes a fast offline attacker guessing about 10 billion hashes per second against a leaked database. Real-world times vary with the hashing algorithm, but it is a useful relative guide.

Length above all, plus a mix of character types and no predictable words or patterns. A random passphrase of four or more unrelated words is both strong and memorable.

Because rules are not entropy. "P@ssw0rd1" satisfies nearly every complexity rule ever written and is genuinely terrible — those substitutions are the first thing cracking tools try.

75 bits or more on anything important. Below about 50 bits is within reach of a determined offline attack against a leaked password hash.

Length, clearly. Adding four characters raises entropy far more than swapping a letter for a symbol.

Four random unrelated words are. A quote or song lyric is not — that is guessable text rather than random choice, and word-list attacks handle it easily.

Nothing is transmitted, logged, or stored — the analysis runs entirely in your browser. Even so, testing a similar pattern rather than your live password is the better habit.