🛡️ Password Strength Checker
Type a password to see an entropy estimate and a rough offline crack-time guess. Everything happens in your browser — the password is never transmitted, logged or stored.
What the score is measuring
The checker sees which character classes appear and adds up a pool - 26 lowercase, 26 uppercase, 10 digits, 33 for anything else, 95 in all. Crack time assumes an offline attacker at ten billion guesses a second:
bits = length x log2(pool)
seconds = 2^bits / 10^10 / 2
Summer2024! 11 x log2(95) = 72 bits -> 74.9 centuries
That verdict is wrong, and usefully so: Summer2024! uses all four classes and trips none of the warnings, yet a wordlist with mangling rules reaches it in seconds. The formula holds only for characters chosen at random.
The bands and the extra checks
- Under 28 bits is Very weak, then Weak to 40, Fair to 60, Strong to 80, Very strong above. The meter reads against 100 bits.
- Thirty of the most common passwords are matched exactly and case-insensitively; a hit forces the score to 0 bits.
- Separate flags catch runs like
123orqwe, a character repeated three times, a single character class, and anything shorter than eight.
Frequently asked questions
Is it safe to type a real password into a strength checker?
Here, yes - the maths runs in your browser and no request leaves the page. As a habit it is a bad one: most checkers give you no way to confirm that, and a copy of your password in someone's log is worth more than the score.
Why does an obvious password score as Strong?
Because it counts character types, not predictability. It cannot see that a word is in a dictionary, that a number is this year, or that 4 stands in for A. A word plus a date plus a symbol is far weaker than the bits suggest.
What crack time should actually worry me?
Read the 10 billion per second figure as a worst case for a fast, unsalted hash. Eight random characters from the full 95 is 53 bits, or about five days, which is not enough. Anything you would rather not lose belongs above 80 bits.