Password Strength Checker

See how long a password would take to crack and what makes it weak: common passwords, dictionary words, dates, repeats, or keyboard patterns. The check runs on your device and the password is never sent.

Updated
Checked in your browser. The password is never sent, stored, or logged.
Online: 10,000 guesses a second. Offline: 10 billion a second. Generate a strong password

How to use the Password Strength Checker

  1. Type a password into Password to check. Press Show if you want to see what you typed.
  2. Read the rating, the strength in bits, and the time an Online attack and an Offline attack would take on average.
  3. Follow the points under What makes it weaker and How to improve it, or press Generate a strong password.

How it works

The checker estimates how many guesses an attacker would need, the way modern cracking tools work: they try common passwords and patterns first, not every combination.

  • A password on the list of the 1,000 most common passwords is rated by its position on the list.
  • Otherwise each character is worth log2(pool) bits, where the pool depends on the kinds of characters used (26 lowercase, 26 uppercase, 10 digits, 33 symbols).
  • Parts that match a pattern are worth much less: a common word counts as one pick from a 3,000-word list, a year as one of 140, a run like aaaa or 1234 as a few bits. Swaps such as @ for a and 0 for o are undone before matching.
  • Crack time is half the guesses divided by the guessing speed: 10,000 per second for an online attack, 10 billion per second offline against a fast hash.
  • Ratings: under 50 bits Weak, 50-79 Fair, 80-127 Strong, 128 and up Very strong.

Examples

  • password and P@ssw0rd are both rated Weak: they are among the most common passwords, swaps or not.
  • Summer2024! is Weak (about 21 bits): a common word, a year, and one symbol.
  • monkey12 can be guessed in about a second online.
  • A random 16-character password such as xK9#mQ2$vL7!pR4& rates Strong, at over 100 bits.

Limitations

  • This is an estimate. Real attackers use larger word lists and leaked-password databases, so treat Fair as weak for anything important.
  • Words that aren't on the 3,000-word list count as random letters, so passphrases made of rare words can be rated higher than they deserve.
  • A strong password still fails if it is reused on a site that gets breached. Use a different password for every account.
  • Don't test your real, current passwords on any website you don't trust. This page runs offline, but the habit is risky.

Frequently asked questions

Is it safe to type my password here?

The check runs entirely in your browser. The password is not sent, stored, logged, or put in the page address. You can disconnect from the internet and it still works.

What makes a password strong?

Length and randomness. A random 16-character password, or a passphrase of five or more random words, beats a short password full of symbols.

Why is p@ssw0rd rated weak?

Cracking tools try common letter swaps automatically. Replacing letters with look-alike symbols adds almost no strength.

What is the difference between online and offline attacks?

Online, the attacker has to try each guess through a login form, which is slow and rate-limited. Offline, they have a stolen password hash and can try billions of guesses a second.

Often used together with the Password Strength Checker.

  • Password Generator

    Creates strong random passwords with a chosen length and character set.

  • Bcrypt Generator

    Creates bcrypt password hashes and checks passwords against existing hashes.

  • Htpasswd Generator

    Creates .htpasswd lines with bcrypt, APR1-MD5, or SHA-1 hashes for Basic Auth.