Password Strength

Measure entropy, crack-time estimate, and security criteria — all in your browser

🔒 Password never leaves your browser

🔑

Type a password above to see strength analysis

About the Password Strength Checker

This password strength checker estimates how resistant a password is to cracking and names the patterns weakening it — dictionary words, keyboard runs, predictable substitutions. Everything is analysed in your browser and nothing is transmitted.

A password strength checker measures resistance to guessing rather than compliance with a rule. That distinction matters, because "P@ssw0rd1!" satisfies almost every complexity policy ever written and is among the first things any cracking tool tries.

Real weakness comes from predictability. Dictionary words, names, dates, keyboard runs like qwerty, and the standard substitutions — @ for a, 0 for o, 1 for l — are all patterns attackers model explicitly, so they add far less strength than their character variety suggests.

Length is the honest lever. Each extra character multiplies the work required, which is why a long unremarkable passphrase beats a short cryptic one. Analysis happens entirely in your browser, so no password you test is transmitted — though testing a password you actually use is still best avoided on any site.

How to use the Password Strength Checker

  1. Type a password. Enter the password you want assessed.
  2. Read the estimate. See roughly how long it would take to crack.
  3. Check the weaknesses. Look at which patterns were detected and why they hurt.
  4. Lengthen it. Add characters and watch the estimate change.

Password Strength Checker features

  • Crack-time estimate rather than a rule checklist
  • Detects dictionary words, names and dates
  • Flags keyboard runs and predictable substitutions
  • Shows the effect of each additional character
  • Nothing typed is transmitted or stored
  • Runs entirely in your browser

Frequently asked questions

Why does my complex password score badly?

Complexity rules are not the same as unpredictability. Patterns like P@ssw0rd are modelled explicitly by cracking tools despite meeting every rule.

Does length or complexity matter more?

Length. Every extra character multiplies the search space, so a long ordinary passphrase beats a short cryptic password.

Is it safe to type a real password here?

Analysis happens entirely in your browser and nothing is transmitted. Even so, avoid typing passwords you actively use into any website.

What patterns weaken a password?

Dictionary words, names, dates, keyboard runs such as qwerty, and predictable substitutions like @ for a or 0 for o.

How long should a password be?

At least 16 characters for anything important, and 20 or more for a password manager master password.