🗒️ Common Password Checker
Checks your password against a static list of about 50 extremely common and frequently breached passwords. This never leaves your browser — nothing is sent anywhere. A "not found" result is not a guarantee the password is safe, only that it isn't on this small sample list.
What the check actually does
The page carries a hard-coded list of 68 passwords - the ones that top every
published breach analysis, plus the obvious keyboard walks and a few
leet-spellings such as passw0rd and p@ssw0rd. What you
type is lower-cased and compared for an exact match against that list:
found = LIST.includes(input.toLowerCase())
That is a whole-string match, not a substring one. Password123 is
flagged; Password123! is not, even though a real cracking wordlist
would reach it within seconds.
Reading the result honestly
- Found is conclusive. Stop using that password everywhere it appears, starting with your email account.
- Not found means only that it missed 68 strings. The public breach corpora that credential-stuffing attacks run from hold hundreds of millions of entries, so this cannot clear a password.
- Commonness and strength are separate questions:
zaq1zaq1passes most complexity rules and is still on the list.
Frequently asked questions
Is password123 a common password?
Yes, and so are password1, passw0rd and p@ssw0rd. All four are on this list and in the top few thousand of every breach dump, which means an attacker reaches them in the first moments of a guessing run.
Does typing my password here send it anywhere?
No. The 68-word list is part of the page and the comparison happens in JavaScript on your device. Nothing is transmitted, stored or written to the page URL.
My password was not on the list, so is it strong?
Not necessarily. Passing this only rules out 68 strings. Strength comes from length and unpredictability - check the bits with the entropy calculator, and use it on one site only.