🔒 Password Strength Checker
See how strong your password really is — its entropy, a Very Weak to Very Strong rating, and an estimate of how long it would take to crack. Everything runs in your browser; nothing is sent to a server.
🔐 Test a Password
🔒 Runs entirely in your browser. Your password is never scanned, transmitted, or stored on a server — this is an educational estimate only.
What is this Password Strength Checker?
It measures how hard a password would be to guess by estimating its entropy — the number of bits of unpredictability it carries. The more character types you draw on and the longer the password, the larger the search space an attacker must brute-force, and the higher the entropy.
The tool then maps that entropy to a plain-language strength label and an order-of-magnitude crack-time estimate. Use it to sanity-check the passwords you rely on — and lean on a password manager to generate and store long, unique ones for every account.
❓ Frequently Asked Questions
How is password strength measured here?
By entropy, a measure of how unpredictable the password is, in bits. First we size the search space from the character types you use (lowercase, uppercase, digits, symbols) and multiply its logarithm by the length. That figure is exact only if every character was picked at random, so we also look for what attackers try first: common passwords and words (with capitals, symbol swaps and numbers added), sequences, repeats, keyboard runs, years and passphrases. The estimate is the smaller of the two. Our pattern list is short: it cannot see names, pets, places or words it does not hold, so a good score does not prove a password is random.
Is my password sent anywhere when I test it?
No. The entire calculation runs locally in your browser using JavaScript. Your password is never scanned, transmitted, logged, or stored on any server. You can even disconnect from the internet and it will still work.
What does the crack-time estimate assume?
It assumes an offline attacker who has stolen the password database and can try about 10 billion guesses per second against a fast, unsalted hash — a high-end but realistic figure. It is a worst-case, order-of-magnitude estimate, not a guarantee.
Why does a long simple password beat a short complex one?
Entropy grows linearly with length but only logarithmically with character-set size. Adding characters multiplies the number of possibilities far faster than adding symbol types to a short password. Words picked at random (with dice, from a list of 7,776) are worth about 12.9 bits each: four words is about 51.7 bits, level with an eight-character random jumble (52.4 bits), and six or seven words pass it easily while staying easier to remember. Words you choose yourself are worth less.