Type or paste a password to see a 0-4 verdict, a six-point checklist with fix hints, an entropy estimate and an illustrative crack time.
Nothing leaves the page: no submit button, no network request, no storage of what you type.
Nothing leaves the page — no submit, no storage. Open the Network tab and check for yourself: typing fires zero requests.
The timer assumes the worst case of offline fast-hash cracking: MD5 or NTLM dumps really can be attacked billions of times per second, while modern bcrypt/scrypt/Argon2 servers slow every guess down — real risk usually comes from password reuse, not brute force.
Want a strong one you can actually remember? Open the passphrase generator
The verdict blends three honest signals: length tiers, character classes and a pattern screen. A curated list of roughly 120 notorious passwords (plus a leet-normalized compare, so p@55w0rd is caught) flags the classics; separate detectors catch four-character sequences — abc, 123, keyboard rows, forwards and reversed — triple repeats, and date or email shapes. Charset entropy is reported alongside as a plain length × log2(charset) estimate, not sold as a guarantee.
On this page, yes: there is no network code at all — the checker reads the field with plain JavaScript and never sends it anywhere. If you want proof, open your browser's developer tools, switch to the Network tab and type away: zero requests fire. Still, checking brand-new passwords or ones you use at banks is a habit worth skipping; samples work fine.
Dropbox's zxcvbn ships multi-megabyte frequency lists from real breach corpora plus a match engine for patterns, dates and keyboards. This page is honest about being a curated subset: roughly 120 classic worst-offenders, sequence and repeat detectors, and charset entropy. It catches obvious passwords and scores structure, but it cannot know your personal breach exposure.
Current NIST guidance says routine scheduled expiry does more harm than good — people pick predictable variations. Change a password when there is evidence of compromise (a breach notice, reused service that got dumped) and make every account unique so one leak stays one leak.
This page does not recommend products. Any reputable manager with local encryption, cross-device sync you can verify and a strong open master-password flow will do; the bigger wins are using one at all, giving every site a unique random credential, and turning on 2FA where available.
No. Scoring is deterministic client-side JavaScript with no submit button, no storage and no requests. Close the tab and the password is gone — nothing persists beyond your screen.
If you just finished with Password Strength Checker, the natural next steps are Morse Code Translator, Word Frequency Counter, Readability Calculator, or browse every tool in Daily Tools.