Type a password below to get a realistic crack-time estimate — based on real brute-force math, not a marketing gauge.
Nothing you type into the password field is stored, logged, or sent anywhere. This tool runs entirely in your browser. You can disconnect from the internet after the page loads and it will keep working — proof that nothing is being transmitted. No accounts, no cookies, no analytics tracking what you type.
This tool calculates your password's entropy — a measure of how many possible combinations an attacker would need to try — based on the character types you use and the length of your password. It then estimates how long a brute-force attack would take against a realistic modern offline cracking setup (roughly 10 billion guesses per second, in line with current high-end GPU cracking rigs).
This is an estimate, not a guarantee. Real-world cracking speed varies by hardware, and passwords that appear in known data breach lists can be cracked almost instantly regardless of their theoretical entropy, because attackers try known-leaked passwords first.
Yes. This calculator runs entirely in your browser using JavaScript — your password is never sent to a server, logged, or stored anywhere. You can disconnect your internet after the page loads and the tool will still work, which proves nothing is being transmitted.
Length matters more than complexity. A 16-character passphrase of random unrelated words is typically stronger and easier to remember than an 8-character password crammed with symbols. Aim for at least 12–16 characters, mix character types, and avoid dictionary words, personal information, or patterns like "123" or "qwerty".
Yes — a password manager lets you use a unique, high-entropy password for every account without needing to remember each one, which is significantly more secure than reusing or slightly varying the same password across sites.
Strength only tells you how hard a password would be to guess — it doesn't tell you if that exact password has already leaked in a breach. Try our free Password Breach Checker to check.
Password strength is not a matter of opinion — it is entropy, measured in bits. The meter above calculates it with the standard formula E = L × log₂(R), where L is the length of your password and R is the size of the character pool it draws from (26 for lowercase, +26 for uppercase, +10 for digits, +32 for symbols). Because length sits in the exponent, adding characters beats adding complexity every time.
The estimates assume an offline attack — an attacker who already has a stolen password database and can guess billions of times per second. Anything under 60 bits falls within hours or days of that kind of hardware. Around 80 bits and above, brute force stops being a realistic threat entirely, which is why the meter caps its scale there.
Modern guidance from the US National Institute of Standards and Technology has moved away from forced symbol-swapping and periodic password changes. What actually protects you:
Brute force is the last resort, not the first. Attackers start with leaked password dictionaries, common substitutions, and personal details scraped from social media — which is why Tr0ub4dor&3-style passwords fall in seconds despite looking strong. Randomness, not cleverness, is the defence. Test a few variations above and watch how much more length adds than symbols.
Most people judge a password by how awkward it looks. Security systems judge it by how many guesses an attacker would need before stumbling onto it. Those two things are not the same, and the gap between them is why P@ssw0rd! feels strong and is, in practice, one of the first things any cracking tool tries.
The measure that matters is entropy, expressed in bits. Each extra bit doubles the number of possible passwords. A password with 40 bits of entropy has roughly a trillion possibilities; one with 60 bits has about a million times more than that. Entropy comes from two ingredients multiplied together: how many different characters you could have chosen from, and how many characters long the password is. Length is the more powerful of the two, because it multiplies rather than adds.
Here is the part that catches people out. Entropy only counts if the choice was genuinely unpredictable. If you picked a dictionary word and then applied a rule everybody uses — capitalise the first letter, swap "a" for "@", put an exclamation mark on the end — an attacker's software applies the same rules. Your eight-character password with mixed case, numbers and symbols may only have the strength of a six-letter word, because the decoration was predictable.
Nobody sits at a login screen typing guesses. Real attacks happen offline, against a stolen database of scrambled password hashes, using hardware built for the job. A single modern graphics card can test billions of candidates per second against weaker hashing algorithms. The attack runs in a rough order of effort:
This ordering explains the advice that follows. A password does not need to be unguessable in some abstract sense. It needs to survive steps one to three, which is where almost all real cracking happens.
This tool estimates strength the way a serious attacker would approach the problem, rather than counting character types. It looks for dictionary words inside the password, for common substitutions layered on top of those words, for keyboard patterns, for dates and years, for repeated sequences, and for passwords that match well-known leaked entries. It then estimates how long a determined offline attack would take.
Everything happens inside your browser tab. Nothing you type is sent over the network, stored, or logged, because the analysis is pure JavaScript running on your own device. You can confirm this yourself by disconnecting from the internet after the page loads — the checker keeps working.
Even so, the sensible habit is not to type a password you are currently using into any website, including this one. Type something with the same shape instead. If your real password is your dog's name plus a birth year, test a different name and a different year. The result will be the same, and the habit is a good one to keep.
A poor score is not a reason to add another symbol to the end. It is a reason to change the approach. Four or five random, unrelated words strung together give you more real strength than a mangled single word of the same length, and they are far easier to remember. Our passphrase generator builds these for you.
The bigger win, though, is not strength at all — it is uniqueness. A very strong password reused across ten sites is only as safe as the weakest of those ten. When one of them is breached, attackers take the email-and-password pair and try it everywhere else, a technique called credential stuffing. It works constantly, because password reuse is close to universal. A password manager solves this properly: one strong master passphrase you memorise, and long random unique passwords for everything else that you never have to remember.
Yes, in almost every case. Adding one more character multiplies the number of possible passwords, while adding one more symbol to a short password only adds a little. A sixteen-character phrase of ordinary words is far harder to crack than an eight-character mix of symbols, and much easier to remember.
No. Forced regular changes are no longer recommended by most security guidance, because they push people towards small predictable edits like adding a number on the end. Change a password when there is a reason: a breach notice, a shared device, or any suspicion the account has been accessed.
The analysis runs entirely in your browser and nothing is transmitted or stored. Even so, the best habit is to test a password of the same shape rather than one you actually use, and to apply that rule to every site that offers a strength checker.
A reputable password manager is a large improvement on reusing passwords or keeping them in a notebook. It encrypts your vault with a key derived from your master passphrase, so the provider cannot read your entries. Pick one master passphrase you can remember, make it long, and never reuse it anywhere.
Four to six random unrelated words, chosen by a generator rather than by you, with spaces or hyphens between them. Do not build it from a quote, a lyric, or anything connected to you. You only need to memorise this one, so it is worth the effort of learning it properly.