Skip to content
Password Strength Checker

Password strength checker that shows which parts of your password are weak

Type a password and see the character pool it draws on, the bits it carries, and — the part a coloured bar can never give you — exactly which runs, sequences, dates and dictionary words are costing it, with the arithmetic for each one. It runs entirely in this page: nothing is uploaded, nothing is saved, and it therefore cannot tell you whether your password has appeared in a breach. That limit is real and is explained below.

  • Nothing is uploaded or saved
  • Works offline
Your password
Try
What this password is made of

Nothing typed yet. The estimate starts from the character types you use — lowercase adds 26 to the pool, uppercase another 26, digits 10, punctuation 32, a space 1 — then takes back whatever the scan can recognise: repeated runs, sequences, QWERTY runs, years, dates, 220 common passwords and 2,048 everyday words.

Estimate
—
0.0 bits

Type something above.

The bands this page uses
Very weakunder 28 bits
Weak28 – 35
Fair36 – 59
Strong60 – 79
Very strong80 and up
Time to guess
Average time to find it
—

The database has leaked and the passwords were stored with a fast, unsalted hash. Ten billion guesses a second is the order of magnitude assumed for rented GPUs. Assume this one — you never find out which was used.

What this cannot tell you

Whether this password has appeared in a data breach. Answering that means sending something derived from it to a service holding the breach corpus, and this page makes no network requests at all — which is the reason it is safe to type a real password into. So a password rated strong here and sitting in a leaked list is still worthless: attackers try known passwords first. Strength and exposure are two different questions, and only one of them can be answered locally.

How it works

  1. 1

    Type or paste — it goes nowhere

    The estimate updates on every keystroke, because a checker with a Check button teaches you nothing about which character mattered. There is no request, no storage and no URL parameter involved, so the only ways your password leaves this machine are the ones you already control: your screen and your clipboard. Use the Hide button if someone is behind you.

  2. 2

    Start with the pool and the bits per character

    The first thing the page works out is which kinds of character you used: lowercase adds 26 to the pool, uppercase another 26, digits 10, punctuation 32, a space 1, and anything outside ASCII an assumed 100. Add those up and take the base-2 logarithm, and you have the value of one character. A lowercase-only password is 4.70 bits per character; add digits and it is 5.17; use all four ASCII classes and it is 6.55.

  3. 3

    Then read what the patterns take back

    Length × bits per character is only right when every character was an independent random draw. Almost none are. The page scans for repeated runs, alphabetical and numerical sequences, straight runs along a QWERTY row, years, dates, the 220 common passwords it carries and the 2,048 everyday words it knows — and replaces each stretch it finds with what that stretch is really worth. Every replacement is shown with its own sentence and its own sum.

  4. 4

    Pick the attack you are worried about

    A time-to-crack figure means nothing without a guessing rate, and this page does not know how the site you use stores your password. So the rate is yours to choose between three named scenarios — a throttled login form at ten guesses a second, a leaked database hashed slowly at ten thousand a second, and a leaked database hashed fast at ten billion a second. Assume the fast one. You never find out which you got.

  5. 5

    Read the band as a rough shelf, not a grade

    The five bands here are a convention this page states outright rather than a measurement: under 28 bits is Very weak, 28–35 Weak, 36–59 Fair, 60–79 Strong, and 80 or more Very strong. Another site’s meter will disagree with this one, and neither is wrong in the way a thermometer can be wrong. What is comparable between them is the bit count and the reasoning, which is why both are on screen.

Frequently asked questions

Can you tell me whether my password has been in a data breach?

No, and nothing on this page will ever claim otherwise. Checking a password against breach data means sending something derived from it to a service that holds the corpus — and this page makes no network requests at all, which is the entire reason to use a local tool for this. So please read the verdict correctly: a password that scores Very strong here and appears in a breach corpus is worthless, because attackers try known passwords before they try anything else. Strength and exposure are two different questions, and this page can only answer one of them.

How is the estimate actually calculated?

In two steps you can redo by hand. First, the character classes present are added up into a pool and one character is valued at log2(pool). Second, the password is scanned for patterns, and each pattern found replaces its stretch of characters with what that stretch costs an attacker who knows the pattern. “Summer2024!” is a worked example: the pool is 94, so each character looks like 6.55 bits and the raw figure is 72.1. But “Summer” is in the common list (8.8 bits, not 6 × 6.55), and “2024” is one of 200 years (7.6 bits, not 4 × 6.55). Only the “!” is left as a free character. The estimate lands near 23 bits — a quarter of what the length suggested.

What exactly does it look for?

Runs of the same character three or more long; alphabetical or numerical sequences three or more long, in either direction; straight runs of four or more along a QWERTY row, including the shifted number row; four-digit years from 1900 to 2099; eight-digit dates; a six-digit input that reads as a day, month and year; the 220 common passwords carried in the page; and the 2,048 four-to-six-letter everyday words carried in the page. Simple character substitutions are undone before the last two checks, so “P@ssw0rd” is recognised as “password” with two bits added back for the substitutions.

What does it miss?

A great deal, and knowing what is more useful than the score. Its word list is 2,048 words of four to six letters — a real cracking dictionary runs to millions and includes every name, place, band, film and football club, in every language. So “battery” is seven letters and is counted here as if it were random, which it is not. The famous four-word example built from “correct horse battery staple” is rated as very strong by this page and would fall in seconds to a list that contains the phrase. Obscene passwords, which sit near the top of every real list, were deliberately left out of this one — their absence here does not make them safe. Treat a low score as proof of weakness and a high score as the absence of proof, not as a guarantee.

Why does the generator page give a lower number than this page for the same passphrase?

Because entropy is a property of the process that made a password, not of the string itself, and this is the clearest way to see it. Generate a four-word passphrase on the password generator and it will report 44 bits: four words drawn from a list of 2,048, and 4 × log2(2048) = 4 × 11 = 44. Paste the same passphrase in here and this page will report more, because it can only see what it can prove — it recognises the words, but it has to treat the separators and the ordering as free characters. The generator knows how the string was made. This page is reconstructing an upper bound from the outside, which is exactly what an attacker does, and it is why a checker can never be as certain as a generator.

Is it safe to type a password I actually use?

From this page, yes: there is no request, no localStorage, no cookie and no URL parameter, and you can confirm it by opening your browser’s network panel or by switching the network off entirely — the page carries on working, which a page that phoned home could not do. The remaining risks are the ordinary ones and they are yours: someone reading your screen, a clipboard manager keeping a history, or a browser extension with permission to read page content. If any of those worry you, check a password with the same shape instead — the same length, the same pattern, different characters — because the shape is what this page is judging.

Does adding “!” to the end of my password help?

Barely, and it is the single most predictable thing anyone does. Appending one symbol to a word adds at most log2(32) = 5 bits if an attacker had no idea it was coming — and every cracking rule set has known about it for two decades, so in practice it adds close to nothing. The same goes for capitalising the first letter and for swapping “a” to “@”. This page charges one bit for each of those transformations rather than pretending they are free, and one bit is a factor of two against the millions of times over that four more random characters buy you.

Why does another site’s meter disagree with this one?

Because there is no standard. Most meters score composition rules — has an uppercase, has a digit, is over eight characters — which is why “P@ssw0rd1” often passes them and is one of the first thousand things anyone tries. Meters that estimate entropy have to choose a pattern library and a set of bands, and no two choose the same. This page states its bands and shows every deduction so you can disagree with it specifically. If two meters disagree, take the lower one seriously and the higher one as unproven.

What should I do about a password this page calls weak?

Change it where it matters most first: email, then anything that can reset a password by email, then banking. Length is the cheapest fix — the difference between 12 and 16 random characters from a full alphabet is a factor of about 78 million, and no amount of punctuation in a short password comes close. And the fix that outranks strength entirely is not reusing it: a strong password used on three sites is only as strong as the worst-run of the three, because the breach happens there and the password is then simply looked up.