🛡️ Password Strength Checker

Type a password to see an entropy estimate and a rough offline crack-time guess. Everything happens in your browser — the password is never transmitted, logged or stored.

What the score is measuring

The checker sees which character classes appear and adds up a pool - 26 lowercase, 26 uppercase, 10 digits, 33 for anything else, 95 in all. Crack time assumes an offline attacker at ten billion guesses a second:

bits    = length x log2(pool)
seconds = 2^bits / 10^10 / 2

Summer2024!  11 x log2(95) = 72 bits -> 74.9 centuries

That verdict is wrong, and usefully so: Summer2024! uses all four classes and trips none of the warnings, yet a wordlist with mangling rules reaches it in seconds. The formula holds only for characters chosen at random.

The bands and the extra checks

Nothing is transmitted: the comparison list is part of the page and no request is made after load. The field is deliberately plain text, so mind who can see the screen.

Frequently asked questions

Is it safe to type a real password into a strength checker?

Here, yes - the maths runs in your browser and no request leaves the page. As a habit it is a bad one: most checkers give you no way to confirm that, and a copy of your password in someone's log is worth more than the score.

Why does an obvious password score as Strong?

Because it counts character types, not predictability. It cannot see that a word is in a dictionary, that a number is this year, or that 4 stands in for A. A word plus a date plus a symbol is far weaker than the bits suggest.

What crack time should actually worry me?

Read the 10 billion per second figure as a worst case for a fast, unsalted hash. Eight random characters from the full 95 is 53 bits, or about five days, which is not enough. Anything you would rather not lose belongs above 80 bits.