Password Generator
Creates strong random passwords with a chosen length and character set.
See how long a password would take to crack and what makes it weak: common passwords, dictionary words, dates, repeats, or keyboard patterns. The check runs on your device and the password is never sent.
The checker estimates how many guesses an attacker would need, the way modern cracking tools work: they try common passwords and patterns first, not every combination.
aaaa or 1234 as a few bits. Swaps such as @ for a and 0 for o are undone before matching.password and P@ssw0rd are both rated Weak: they are among the most common passwords, swaps or not.Summer2024! is Weak (about 21 bits): a common word, a year, and one symbol.monkey12 can be guessed in about a second online.xK9#mQ2$vL7!pR4& rates Strong, at over 100 bits.The check runs entirely in your browser. The password is not sent, stored, logged, or put in the page address. You can disconnect from the internet and it still works.
Length and randomness. A random 16-character password, or a passphrase of five or more random words, beats a short password full of symbols.
Cracking tools try common letter swaps automatically. Replacing letters with look-alike symbols adds almost no strength.
Online, the attacker has to try each guess through a login form, which is slow and rate-limited. Offline, they have a stolen password hash and can try billions of guesses a second.
Often used together with the Password Strength Checker.
Creates strong random passwords with a chosen length and character set.
Creates bcrypt password hashes and checks passwords against existing hashes.
Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.