Password Strength Checker
Processed Client SideAnalyze password entropy, estimate crack time, and get concrete tips to make it stronger. Everything runs in your browser — nothing is sent anywhere.
Bookmark this tool now — skip the search next time you need it.
About Password Strength Checker
This tool runs entirely in your browser. Whatever you paste is processed on your own device and is never uploaded, logged, or sent to any server.
Measure how strong a password actually is, using entropy rather than the arbitrary rules most sites enforce. It reports the size of the character pool, the length, the resulting entropy in bits, and an estimated time to crack, alongside a checklist of the criteria the password meets. The distinction that matters is between rules and entropy: "P@ssw0rd1" satisfies almost every complexity rule ever written and is genuinely terrible, because the substitutions are the first thing any cracking tool tries. Entropy measures the actual search space, which is the number that determines how long a real attack takes.
Key features
- Entropy calculated in bits from the character pool and length
- Estimated crack time expressed in human terms
- Character pool size and length reported separately, so you can see which one is limiting you
- Criteria checklist covering length, uppercase, lowercase, digits, and symbols
- Common-password detection, which drops the rating regardless of what the rules say
- Five strength bands from Very Weak to Very Strong
- Show and hide toggle for the password field
- Runs entirely in your browser — nothing is transmitted, logged, or stored
How to use it
- Type or paste the password into the field.
- Read the entropy figure and the estimated crack time.
- Check which criteria it fails.
- Lengthen it — that raises entropy faster than adding another symbol.
Tips & common mistakes
- Entropy is the number that matters. Aim for 75 bits or more on anything important; below about 50 bits is within reach of a determined offline attack.
- Length beats complexity. Adding four characters raises entropy far more than swapping an a for an @, and the substitution tricks are in every cracking dictionary already.
- Crack-time estimates assume an offline attack against a leaked hash. An online login with rate limiting is much slower to attack — but you should assume the hash will leak.
- A password matching a known common password is rated very weak no matter how many rules it passes, because attackers start from those lists.
- Four random unrelated words make a strong and memorable passphrase. A quote or a song lyric does not, because it is guessable text rather than random choice.
- Nothing you type here is transmitted or stored — it is all in-browser. Even so, prefer testing a pattern similar to your real password rather than the live one.
- The real fix is a password manager generating a unique password per site. Strength on a reused password is undone the moment any one site is breached.
- Need a strong password rather than just a rating for an existing one? Generate one with the Password Generator.