What this tool checks
- Length and character variety
- Entropy (bits)
- Common password and word matches
- Keyboard patterns, sequences and repeats
- Estimated crack time for online and offline attacks
- Optional: seen in known breaches (k-anonymity)
How to use it
- 01
Type a password; analysis happens in your browser as you type.
- 02
Look at the estimated crack times and suggestions.
- 03
Optionally check whether the password appears in known data breaches.
Technical details
Your password is not sent
All calculations run in your browser. If you choose the breach check, only the first 5 characters of the password's SHA-1 hash are sent (k-anonymity); the password or full hash never leaves your device.
How entropy is calculated
Raw entropy is computed from the character pool, then reduced for common passwords, dictionary words, keyboard patterns, dates and repeats. The result is closer to the number of guesses an attacker actually needs.
Crack time scenarios
Online attacks are rate-limited; offline attacks try leaked hashes on GPUs. Slow hash functions (bcrypt, Argon2) widen that gap dramatically.
Frequently asked questions
Is it safe to type my password here?
Analysis runs entirely in your browser and the password is not sent to our server. Still, testing a similar example instead of your real password is a good habit.
What makes a good password?
At least 14–16 characters: a passphrase of several randomly chosen words, or a random string from a password manager. Most important: a different one for every account.
Are special characters required?
Length beats complexity. Current NIST guidance also favors length and breach screening over composition rules.
Is a strong password enough?
No. Passwords can also be phished; always use multi-factor authentication on important accounts.