Password Strength Checker

Check how strong a password is: entropy, cracking time and common weaknesses — privately in your browser.

Runs instantly in your browser — results update as you type.

How strong is my password?

Password strength is how hard a password is to guess. It depends mostly on length and randomness, measured as entropy in bits; common words, keyboard patterns and dates make a password much weaker than its length suggests.

What is checked

  • Entropy — estimated from the length and the types of characters used.
  • Common passwords and words — including "leet" variants such as P@ssw0rd.
  • Patterns — repeated characters, keyboard and number sequences, years.
  • Cracking time — for an offline attack at 10 billion guesses per second.

What makes a strong password

  1. At least 12–16 characters — length beats complexity.
  2. Random words or characters, not personal information.
  3. A different password for every site, kept in a password manager.
  4. Two-factor authentication wherever possible.

Create one with the Strong Password Generator. The password you type is never sent anywhere.

Frequently asked questions

Is it safe to type my real password here?

The check runs only in your browser and nothing is sent. Still, consider testing a similar password instead of your real one.

Why is my long password rated weak?

It probably contains a common word, a pattern like 1234 or a repeated character.

How accurate is the cracking time?

It is an estimate for a fast offline attack; real attacks may be slower or faster depending on how the password is stored.