Password Strength Checker

Type a password to see how guessable it is. The check runs entirely in this page — nothing is sent, logged or stored.

Runs in your browser — nothing is uploaded

Start typing to check strength.

Checked locally — the password never leaves this page.

Details

Offline attack (fast hash, 10 billion/s)—
Offline attack (slow hash, 10,000/s)—
Online attack (10/s, no lockout)—
Entropy (estimated)—
Length · character set—
Patterns found—

    How to use Password Strength Checker

    1. Type or paste a password (use a similar one if you prefer not to test your real password).
    2. Read the score, estimated crack times and entropy.
    3. Follow the tips, or generate a strong password instead.

    Questions

    Is it safe to type my password here?

    The check runs entirely in your browser with JavaScript; the password is not sent over the network, not saved, and not included in analytics. You can even disconnect from the internet after the page loads. If in doubt, test a password with the same structure instead of your real one.

    How is the crack time estimated?

    The password is broken into patterns attackers try first — common passwords, dictionary words, keyboard runs, sequences, repeats and dates — and the number of guesses needed is estimated from those. Times assume an attacker making 10 billion guesses per second against a fast, unsalted hash, or much slower online guessing.

    What makes a password strong?

    Length and unpredictability. A random 16-character password, or a passphrase of four or more random words, is far stronger than a short word with symbols swapped in. Use a different password for every account and keep them in a password manager.