Password Strength Checker
Type in a password you already use to see a real entropy estimate, an estimated crack time, a full pass/fail checklist, and pattern warnings — checked entirely on your device.
- ✗ Lowercase letters
- ✗ Uppercase letters
- ✗ Numbers
- ✗ Symbols
- ✗ 8+ characters
- ✗ 12+ characters
- ✗ Not a common password
- ✗ No simple patterns
Nothing you type here is ever transmitted, logged, or saved — it only exists in your browser's memory for as long as this page is open.
How to Check a Password's Strength
- Type the password you want to check into the field (click the eye icon to reveal it as you type).
- The strength meter, entropy estimate, estimated crack time, and full pass/fail checklist update live with every keystroke.
- Watch for any red pattern warnings below the checklist — these flag common passwords, repeated characters, or predictable sequences.
- Aim for a genuinely random password of 12+ characters mixing all four character types, with no warnings shown.
Frequently Asked Questions
Is my password sent anywhere or stored?
No — it's analyzed entirely in your browser's memory and never transmitted, logged, or saved. Nothing you type here is written to localStorage, sent over the network, or included in any analytics.
Does this check my password against known data breaches?
No — that would require sending your password to an external server, which this tool deliberately never does. It only analyzes your password's own structure, such as its length, character variety, and predictable patterns, entirely locally.
How is the entropy in bits actually calculated?
The tool multiplies your password's length by log2(N), where N is the combined size of the character pools actually present — lowercase letters, uppercase letters, digits, and symbols — a standard way to estimate how large the search space would be for someone guessing it.
Why is a short password flagged as weak even if it mixes character types?
Length matters more than variety for real-world resistance to guessing, so any password under 8 characters is automatically flagged as weak, regardless of how many character classes it uses.
Why was my password flagged as one of the most common passwords?
This tool checks your input against a built-in list of over 100 of the most common leaked and predictable passwords — things like "password", "123456", and "qwerty123" — checked as case-insensitive substrings. If your password matches or contains one of these, it's flagged as weak no matter what the calculated entropy says, because these are the very first passwords a real attacker tries.
How is the estimated crack time calculated?
The crack-time estimate treats your password as a random string drawn from the character pools it actually uses, then assumes an attacker needs to try about half of all possible combinations on average. That number of guesses is divided by two stated guessing speeds: roughly 10 billion guesses per second for a fast offline attack against a stolen password hash, and roughly 100 guesses per second for an online attack against a rate-limited login form. These are brute-force estimates only — a password that's common or follows a predictable pattern (flagged separately above) can be guessed far faster in practice, regardless of its raw entropy.
What counts as a "simple pattern" that weakens my password?
The tool flags a handful of well-known weaknesses: keyboard walks like "qwerty" or "asdfgh", ascending or descending runs of 4 or more characters like "1234" or "dcba", and any character repeated 3 or more times in a row like "aaa". These patterns make a password far easier to guess than its length or character variety alone would suggest, so they're checked and flagged separately from the entropy calculation.