About Password Strength Checker
This password strength checker estimates how many guesses an attacker would need to find your password and turns that into time for five attackers: a website that limits tries, a website with no limit, an offline attack on a slow hash such as bcrypt, an offline attack on a fast hash such as MD5, and a large cracking cluster. It also shows the weak spots it found and how to fix them.
The estimate looks for common passwords, words and names, look-alike substitutions such as @ for a, reversed words, keyboard patterns like qwerty, runs like abc or 1234, repeats, years and dates, and prices the rest as random characters. Your password is analysed in your browser only and is never sent, stored or logged, but do not test a password you still use on an important account.
How to use Password Strength Checker
- 01
Type or paste a password. It never leaves your browser.
- 02
See the strength, the estimated guesses and the time to crack for different attackers.
- 03
Read the weak spots and tips, then improve it or generate a new one.
When to use it
- Check whether a password is worth keeping or should be replaced.
- Show a team or family why length beats clever substitutions.
- Compare a random password with a passphrase of random words.
- See which part of a password makes it weak: a word, a year or a pattern.
- Decide how long a master password for a password manager should be.
Frequently asked questions
Is it safe to type my password here?
The check runs entirely in your browser: nothing is sent, stored or logged. Even so, do not test a password you still use on an important account; test a similar one instead.
How is the time to crack calculated?
The checker estimates how many guesses an attacker would need, using common passwords, words, keyboard patterns, dates and character sets, then divides by guesses per second for five kinds of attack. The average password falls after half of all guesses.
Why does a long password score higher than a complex one?
Every extra character multiplies the number of possibilities. Length beats tricks such as replacing a with @, because attackers try those tricks first.
What does the strength rating mean?
Very weak is cracked instantly, weak within a second on a fast attack, fair within minutes, good within days and strong needs years even for a cluster of fast GPUs. The ratings follow a fast offline attack because that is the realistic danger after a data breach.
Why is my random password rated lower than the generator said?
The checker only sees the final text. If a random password happens to contain a word, a year or a keyboard pattern, it is priced as the cheaper way to guess it. A password from the generator is rated by the way it was made.
Does it check whether my password was in a data breach?
No, because that would mean sending something about your password to another service. The checker knows a short list of the most common passwords, so a password that appears in a real breach list may be rated better than it deserves. Treat any password that ever leaked as burnt.