↑↓ to move ↵ to open Esc to close Browse all tools

Password Strength Checker

Type a password to see how long it would take to crack, which patterns give it away, and how to make it stronger. Nothing leaves your browser.

No network requests: the word lists and the math are part of this page.

Start typing to see the strength.

Checked on your device. The page makes no network requests while you type, and nothing is stored.

How the password strength checker works

Cracking tools do not try every combination of characters in order. They start with lists of leaked passwords and dictionary words, add capitals, digits and symbols in the places people put them, swap letters for look-alike symbols, and try keyboard rows and dates. This checker estimates how many guesses that kind of tool needs for your password.

It splits the password into the cheapest pieces it can find, such as a common word, a year or a run of random characters, and adds up their cost in bits of entropy. The number in the "if it were random" box is what a truly random password of the same length and character types would have. The bigger the gap between the two, the more predictable your password is.

Random characters
bits = length × log2(pool)
Average crack time
2bits − 1 ÷ guesses per second

Example passwords and their strength

The same estimator, on passwords that look complex but follow familiar patterns. Crack times are for a fast offline attack at 100,000,000,000 guesses per second.

PasswordEstimatedIf randomRatingOffline, fast hash
password13 bits47 bitsVery weakinstantly
Summer2024!21 bits72 bitsVery weakinstantly
P@ssw0rd!10 bits59 bitsVery weakinstantly
qwerty1236 bits47 bitsVery weakinstantly
kX9#mQ2$vL7!pR4z105 bits105 bitsVery strongmore than 100,000 years

Getting a strong password

The surest way is not to invent one. The password generator creates random passwords with your browser's cryptographic random number generator, and its passphrase mode strings random words together for passwords you have to type or remember. Use a different password for every account, so one leak does not open the others.

If a site was breached, change that password first, then every account where you reused it. Turn on two-factor authentication wherever it is offered; it protects you even when a password does leak.

Frequently asked questions

Is it safe to type my real password here?

The checker makes no network requests: the word lists and the math are part of the page, and nothing you type is stored or sent. You can confirm this in your browser's network tab, or load the page and switch off your connection before you type. As a habit, never enter a password on a site you do not trust.

How is the strength calculated?

It looks for the patterns cracking tools try first: common passwords, dictionary words, l33t spellings, keyboard walks, sequences, repeats, years and dates. Then it finds the cheapest way to build your password from those pieces plus random characters and counts the guesses that takes. The result is shown in bits, where each extra bit doubles the work.

What do the crack times mean?

They are the average time to find the password at four guessing speeds: an online login that is rate limited, an online login without limits, and two offline attacks on a stolen database, one with a slow password hash like bcrypt and one with a fast hash like MD5 on graphics cards. Real attackers vary, so read the times as orders of magnitude.

Why is my long password rated weak?

Length only helps when the characters are unpredictable. A long password made of a common word, a year and an exclamation mark is cracked early because each of those parts is one cheap guess, not many random characters.

What makes a password strong?

Randomness and length. A password manager can create and remember 16 or more random characters for every account. For the few passwords you must type or remember, use a passphrase of five or more random words.