Password Strength Checker

Type or paste a password to see a 0-4 verdict, a six-point checklist with fix hints, an entropy estimate and an illustrative crack time.

Nothing leaves the page: no submit button, no network request, no storage of what you type.

Nothing leaves the page — no submit, no storage. Open the Network tab and check for yourself: typing fires zero requests.

Type or paste a password to see the assessment.

Checks

    The timer assumes the worst case of offline fast-hash cracking: MD5 or NTLM dumps really can be attacked billions of times per second, while modern bcrypt/scrypt/Argon2 servers slow every guess down — real risk usually comes from password reuse, not brute force.

    Want a strong one you can actually remember? Open the passphrase generator

    How It Works

    The verdict blends three honest signals: length tiers, character classes and a pattern screen. A curated list of roughly 120 notorious passwords (plus a leet-normalized compare, so p@55w0rd is caught) flags the classics; separate detectors catch four-character sequences — abc, 123, keyboard rows, forwards and reversed — triple repeats, and date or email shapes. Charset entropy is reported alongside as a plain length × log2(charset) estimate, not sold as a guarantee.

    What attackers actually do
    Most account takeovers today are credential stuffing — replaying leaked email/password pairs — not brute force, because a reused password is already known. That is why unique-per-site beats strong-but-shared, and why the checklist rewards structure instead of just the exclamation mark and digit.
    The offline-hash caveat behind crack times
    If a site stores MD5 or NTLM hashes, a consumer GPU farm tests billions of candidates per second and the illustrative timer here is roughly real. Modern bcrypt, scrypt or Argon2 servers make each guess slow and memory-hungry, so the same number is wildly pessimistic — the estimate is a yardstick, not a forecast.
    Why "special characters mandatory" aged out
    NIST's digital identity guidelines dropped forced periodic rotation and stopped treating symbol counts as a security feature: users respond with predictable templates like a capital letter up front and "!" at the end. Length, unpredictability and uniqueness are the levers that still move the needle.

    Frequently Asked Questions

    Is typing my real password here safe?

    On this page, yes: there is no network code at all — the checker reads the field with plain JavaScript and never sends it anywhere. If you want proof, open your browser's developer tools, switch to the Network tab and type away: zero requests fire. Still, checking brand-new passwords or ones you use at banks is a habit worth skipping; samples work fine.

    How is this different from zxcvbn?

    Dropbox's zxcvbn ships multi-megabyte frequency lists from real breach corpora plus a match engine for patterns, dates and keyboards. This page is honest about being a curated subset: roughly 120 classic worst-offenders, sequence and repeat detectors, and charset entropy. It catches obvious passwords and scores structure, but it cannot know your personal breach exposure.

    Should I change my passwords every few months?

    Current NIST guidance says routine scheduled expiry does more harm than good — people pick predictable variations. Change a password when there is evidence of compromise (a breach notice, reused service that got dumped) and make every account unique so one leak stays one leak.

    Which password manager should I use?

    This page does not recommend products. Any reputable manager with local encryption, cross-device sync you can verify and a strong open master-password flow will do; the bigger wins are using one at all, giving every site a unique random credential, and turning on 2FA where available.

    Is anything uploaded to a server?

    No. Scoring is deterministic client-side JavaScript with no submit button, no storage and no requests. Close the tab and the password is gone — nothing persists beyond your screen.