Home › Web & Security

Password Strength Checker

Score a password on length and character variety, see the estimated entropy and offline crack time, and get per-rule feedback. Nothing is transmitted or stored.

0Score (0-4)
-Verdict
0Entropy bits
-Offline crack time

How the score is built

Entropy is the honest number here: it is the length multiplied by the bits each character position could have carried, given the character sets in play. Length dominates, which is why a four-word passphrase beats a nine-character mix with a symbol in it, and why the score does not move much when you swap one digit for another. The crack time assumes an offline attacker testing ten billion guesses per second against a slow hash, and it shows the median case - half the keyspace - rather than the worst case.

The score itself is a four-step summary over entropy plus a penalty for patterns a cracker would skip straight to: repeating characters, straight keyboard runs, and single digits appended to a word. That last one is why summer2026 scores lower than the raw bit count suggests - dictionaries already contain the pattern, so the effective search space is smaller than the character count implies.

Usage example

You are deciding between two candidate passphrases for a shared team credential. Score the first, note the bits and the crack time, then score the second. The one worth keeping is usually the longer of the two even if it looks less "complex", and the notes row tells you whether a specific rule - a missing digit, a repeating run - is what is holding the score back, so you know what to change instead of guessing.

Use it against passwords you have already chosen or are composing, never against a live credential you cannot afford to have on screen. For generating something with the properties the checker rewards, the password generator builds one to order, and the SHA hash generator is the right tool when what you actually need is a digest rather than a password.

Frequently asked questions

Does this check whether my password has been leaked?

No. There is no network call of any kind, so it cannot compare against breach corpora. That is deliberate: a checker that uploads candidates would be the wrong tool to trust with one. To check exposure, use a reputable breach-lookup service that accepts a password as a k-anonymity prefix rather than in full.

Why is the crack time an estimate?

It depends on the attacker's hardware, the hashing algorithm and whether the credential is offline or online-throttled. Ten billion guesses per second models a well-resourced offline attack on a fast hash - a deliberately pessimistic baseline, since real attackers against a slow hash land far below it.

Is a high score the same as a good password?

It is a necessary condition, not a sufficient one. The score cannot see that the password is reused across sites, that it contains your username, or that it was chosen because a policy demanded one digit - those are the failures that actually get accounts taken over.

Related tools

Strong Password Generator

Generate strong random passwords using the browser's cryptographic random source. Choose length and character sets; nothing leaves your device.

SHA Hash Generator

Compute SHA-256, SHA-1 and MD5 digests of any text directly in the browser.

UUID Generator

Generate RFC 4122 UUIDs in v4 and v7 flavours, with bulk output and copy-to-clipboard.