🗒️ Common Password Checker

Checks your password against a static list of about 50 extremely common and frequently breached passwords. This never leaves your browser — nothing is sent anywhere. A "not found" result is not a guarantee the password is safe, only that it isn't on this small sample list.

What the check actually does

The page carries a hard-coded list of 68 passwords - the ones that top every published breach analysis, plus the obvious keyboard walks and a few leet-spellings such as passw0rd and p@ssw0rd. What you type is lower-cased and compared for an exact match against that list:

found = LIST.includes(input.toLowerCase())

That is a whole-string match, not a substring one. Password123 is flagged; Password123! is not, even though a real cracking wordlist would reach it within seconds.

Reading the result honestly

The comparison runs on the list embedded in this page. Your password is never hashed, uploaded or logged - there is no network call here at all. To check against a real breach corpus you would need a service like Have I Been Pwned, which uses a hash-prefix lookup so the full password still stays with you.

Frequently asked questions

Is password123 a common password?

Yes, and so are password1, passw0rd and p@ssw0rd. All four are on this list and in the top few thousand of every breach dump, which means an attacker reaches them in the first moments of a guessing run.

Does typing my password here send it anywhere?

No. The 68-word list is part of the page and the comparison happens in JavaScript on your device. Nothing is transmitted, stored or written to the page URL.

My password was not on the list, so is it strong?

Not necessarily. Passing this only rules out 68 strings. Strength comes from length and unpredictability - check the bits with the entropy calculator, and use it on one site only.