Password Strength Checker
Score any password with entropy analysis and crack-time estimates.
Loading tool…
About this tool
Password Strength Checker scores your password on a 0–100 scale using entropy math: it measures the character pool and length, then estimates how long a brute-force attack would take at realistic guess rates. You also get specific, actionable suggestions — the exact weaknesses to fix rather than a vague "weak" label.
Your password is analyzed locally in your browser and is never transmitted, logged, or stored. You can safely test real passwords here.
How to use
- Type or paste the password to evaluate.
- Read the strength score, entropy bits, and crack-time estimate.
- Review the suggestions for concrete improvements.
- Adjust and re-test until the score meets your bar.
Frequently asked questions
Yes — analysis runs entirely in your browser. The password is never sent over the network, logged, or stored anywhere.
They assume an offline brute-force attack at billions of guesses per second against the full character pool. Real attackers also try dictionaries and patterns, so treat the estimate as an upper bound.
Each extra character multiplies the search space by the pool size. A 16-character lowercase password (75 bits) beats an 8-character mixed one (52 bits) despite looking "simpler".
Strength is one layer. Reused passwords, phishing, and breaches matter more in practice — use unique passwords plus 2FA for important accounts.