FREE TOOL · RUNS ON YOUR DEVICE

Password Strength Checker

Type a password below to get a realistic crack-time estimate — based on real brute-force math, not a marketing gauge.


VERIFIED SAFE

Nothing you type into the password field is stored, logged, or sent anywhere. This tool runs entirely in your browser. You can disconnect from the internet after the page loads and it will keep working — proof that nothing is being transmitted. No accounts, no cookies, no analytics tracking what you type.

Test a password
Enter a password above 0 bits
Estimated time to crack (offline attack)
—
Assumes 10 billion guesses/second — a realistic modern GPU cluster
– At least 12 characters
– Contains uppercase letters
– Contains lowercase letters
– Contains numbers
– Contains symbols
– Not a commonly leaked password

How this crack-time estimate works

This tool calculates your password's entropy — a measure of how many possible combinations an attacker would need to try — based on the character types you use and the length of your password. It then estimates how long a brute-force attack would take against a realistic modern offline cracking setup (roughly 10 billion guesses per second, in line with current high-end GPU cracking rigs).

This is an estimate, not a guarantee. Real-world cracking speed varies by hardware, and passwords that appear in known data breach lists can be cracked almost instantly regardless of their theoretical entropy, because attackers try known-leaked passwords first.

Frequently asked questions

Is it safe to type my real password into this tool?

Yes. This calculator runs entirely in your browser using JavaScript — your password is never sent to a server, logged, or stored anywhere. You can disconnect your internet after the page loads and the tool will still work, which proves nothing is being transmitted.

What makes a password actually strong?

Length matters more than complexity. A 16-character passphrase of random unrelated words is typically stronger and easier to remember than an 8-character password crammed with symbols. Aim for at least 12–16 characters, mix character types, and avoid dictionary words, personal information, or patterns like "123" or "qwerty".

Should I use a password manager instead of memorizing passwords?

Yes — a password manager lets you use a unique, high-entropy password for every account without needing to remember each one, which is significantly more secure than reusing or slightly varying the same password across sites.

A strong password isn't the whole story

Strength only tells you how hard a password would be to guess — it doesn't tell you if that exact password has already leaked in a breach. Try our free Password Breach Checker to check.

The Mathematics Behind the Meter

Password strength is not a matter of opinion — it is entropy, measured in bits. The meter above calculates it with the standard formula E = L × log₂(R), where L is the length of your password and R is the size of the character pool it draws from (26 for lowercase, +26 for uppercase, +10 for digits, +32 for symbols). Because length sits in the exponent, adding characters beats adding complexity every time.

What the Crack-Time Estimates Mean

The estimates assume an offline attack — an attacker who already has a stolen password database and can guess billions of times per second. Anything under 60 bits falls within hours or days of that kind of hardware. Around 80 bits and above, brute force stops being a realistic threat entirely, which is why the meter caps its scale there.

Current Best Practice (NIST Guidelines)

Modern guidance from the US National Institute of Standards and Technology has moved away from forced symbol-swapping and periodic password changes. What actually protects you:

How Attackers Actually Crack Passwords

Brute force is the last resort, not the first. Attackers start with leaked password dictionaries, common substitutions, and personal details scraped from social media — which is why Tr0ub4dor&3-style passwords fall in seconds despite looking strong. Randomness, not cleverness, is the defence. Test a few variations above and watch how much more length adds than symbols.

How password strength is actually measured

Most people judge a password by how awkward it looks. Security systems judge it by how many guesses an attacker would need before stumbling onto it. Those two things are not the same, and the gap between them is why P@ssw0rd! feels strong and is, in practice, one of the first things any cracking tool tries.

The measure that matters is entropy, expressed in bits. Each extra bit doubles the number of possible passwords. A password with 40 bits of entropy has roughly a trillion possibilities; one with 60 bits has about a million times more than that. Entropy comes from two ingredients multiplied together: how many different characters you could have chosen from, and how many characters long the password is. Length is the more powerful of the two, because it multiplies rather than adds.

Here is the part that catches people out. Entropy only counts if the choice was genuinely unpredictable. If you picked a dictionary word and then applied a rule everybody uses — capitalise the first letter, swap "a" for "@", put an exclamation mark on the end — an attacker's software applies the same rules. Your eight-character password with mixed case, numbers and symbols may only have the strength of a six-letter word, because the decoration was predictable.

How attackers actually crack passwords

Nobody sits at a login screen typing guesses. Real attacks happen offline, against a stolen database of scrambled password hashes, using hardware built for the job. A single modern graphics card can test billions of candidates per second against weaker hashing algorithms. The attack runs in a rough order of effort:

  1. Known-password lists first. Billions of real passwords have leaked over the years. Every one of them is tried before anything else, because it costs almost nothing and catches a surprising share of accounts.
  2. Dictionary plus rules. Words, names, sports teams, song titles and place names, run through thousands of common mangling rules — append the years 1950 to 2030, swap letters for lookalike numbers, capitalise, reverse, double.
  3. Pattern attacks. Keyboard walks such as qwerty, 1qaz2wsx or zxcvbnm, plus predictable shapes like "one capital, six lowercase, two digits" which describes a large share of all human-chosen passwords.
  4. Brute force last. Every combination, in order. This is the only method that length genuinely defeats, and it is why a long passphrase wins.

This ordering explains the advice that follows. A password does not need to be unguessable in some abstract sense. It needs to survive steps one to three, which is where almost all real cracking happens.

What the checker on this page is doing

This tool estimates strength the way a serious attacker would approach the problem, rather than counting character types. It looks for dictionary words inside the password, for common substitutions layered on top of those words, for keyboard patterns, for dates and years, for repeated sequences, and for passwords that match well-known leaked entries. It then estimates how long a determined offline attack would take.

Everything happens inside your browser tab. Nothing you type is sent over the network, stored, or logged, because the analysis is pure JavaScript running on your own device. You can confirm this yourself by disconnecting from the internet after the page loads — the checker keeps working.

Even so, the sensible habit is not to type a password you are currently using into any website, including this one. Type something with the same shape instead. If your real password is your dog's name plus a birth year, test a different name and a different year. The result will be the same, and the habit is a good one to keep.

What to do with a weak result

A poor score is not a reason to add another symbol to the end. It is a reason to change the approach. Four or five random, unrelated words strung together give you more real strength than a mangled single word of the same length, and they are far easier to remember. Our passphrase generator builds these for you.

The bigger win, though, is not strength at all — it is uniqueness. A very strong password reused across ten sites is only as safe as the weakest of those ten. When one of them is breached, attackers take the email-and-password pair and try it everywhere else, a technique called credential stuffing. It works constantly, because password reuse is close to universal. A password manager solves this properly: one strong master passphrase you memorise, and long random unique passwords for everything else that you never have to remember.

The short version


Frequently asked questions

Is a longer password really better than a complicated one?

Yes, in almost every case. Adding one more character multiplies the number of possible passwords, while adding one more symbol to a short password only adds a little. A sixteen-character phrase of ordinary words is far harder to crack than an eight-character mix of symbols, and much easier to remember.

Do I need to change my passwords every 90 days?

No. Forced regular changes are no longer recommended by most security guidance, because they push people towards small predictable edits like adding a number on the end. Change a password when there is a reason: a breach notice, a shared device, or any suspicion the account has been accessed.

Is it safe to type my password into this checker?

The analysis runs entirely in your browser and nothing is transmitted or stored. Even so, the best habit is to test a password of the same shape rather than one you actually use, and to apply that rule to every site that offers a strength checker.

Are password managers safe?

A reputable password manager is a large improvement on reusing passwords or keeping them in a notebook. It encrypts your vault with a key derived from your master passphrase, so the provider cannot read your entries. Pick one master passphrase you can remember, make it long, and never reuse it anywhere.

What makes a good master passphrase?

Four to six random unrelated words, chosen by a generator rather than by you, with spaces or hyphens between them. Do not build it from a quote, a lyric, or anything connected to you. You only need to memorise this one, so it is worth the effort of learning it properly.

Made in New Zealand 🇳🇿 — sharing good cyber hygiene habits with friends everywhere.
About UsContact UsPrivacy PolicyTerms
👀 … site visits