What is checked
- Entropy — estimated from the length and the types of characters used.
- Common passwords and words — including "leet" variants such as P@ssw0rd.
- Patterns — repeated characters, keyboard and number sequences, years.
- Cracking time — for an offline attack at 10 billion guesses per second.
What makes a strong password
- At least 12–16 characters — length beats complexity.
- Random words or characters, not personal information.
- A different password for every site, kept in a password manager.
- Two-factor authentication wherever possible.
Create one with the Strong Password Generator. The password you type is never sent anywhere.
Frequently asked questions
Is it safe to type my real password here?
The check runs only in your browser and nothing is sent. Still, consider testing a similar password instead of your real one.
Why is my long password rated weak?
It probably contains a common word, a pattern like 1234 or a repeated character.
How accurate is the cracking time?
It is an estimate for a fast offline attack; real attacks may be slower or faster depending on how the password is stored.

