Tools marked “Coming soon” are being built now.

Developer tools
Developer · Free · Private

Password Strength Checker

Type a password and see how an attacker would actually crack it, with no upload and nothing saved.

  • Runs in your browser
  • No upload
  • No sign-up

Checked on your device as you type. Never stored, never sent.

Start typing to see how strong it is.

Need a strong one instead?Make a random password or a memorable passphrase with our Password Generator.Open tool →

About this tool

Most strength meters only count character types, so they call “P@ssw0rd!” strong because it has a capital, a number and a symbol. Real attackers don’t guess that way. They start with lists of leaked passwords, dictionary words and names, then try the tricks people use: a capital at the front, a year or “!” on the end, 0 for o, keyboard runs like qwerty and 1qaz2wsx. This checker thinks the same way.

As you type, it breaks the password into the pieces an attacker would recognise, such as a common password, a word, a name, a date, a sequence, a repeat or a keyboard walk, and works out the cheapest way to guess the whole thing. That estimate becomes an average crack time for four realistic attacks, from a website that limits login attempts to a stolen database being hammered by graphics cards. You also get the specific weaknesses in plain English and concrete ways to fix them.

The check runs entirely in your browser. The password is never stored, logged or sent, and the page makes no network request while you type. There is deliberately no “has it been leaked?” lookup, because that would mean sending something about your password over the internet.

How to use Password Strength Checker

  1. Type or paste a password into “Password to check”. It stays hidden as dots unless you press Show.
  2. Read the meter: Very weak, Weak, Fair, Strong or Very strong, with the estimated number of guesses.
  3. Look at “How long to crack it” for the four attack speeds, especially the online and fast offline ones.
  4. Check “What an attacker would see” for the pieces found and the weaknesses behind the score.
  5. Follow “How to make it stronger”, or open the Password Generator for a random one.
Example

“Tr0ub4dor&3” has every kind of character, yet it scores Weak: it is the word “troubadour” misspelt, with look-alike swaps, a capital at the front and two extra characters. “correct horse battery staple” is all lower-case letters and still scores Strong, because four unrelated words take far more guessing.

Features

  • Pattern-aware estimate built from scratch: common passwords, dictionary words, names, misspellings, look-alike swaps, reversed words and capitals.
  • Spots keyboard walks (qwerty, zxcvb, 1qaz2wsx), number-pad runs, sequences (abcd, 9876), repeats (aaaa, abcabc), years and dates.
  • Average crack time for four attacks: online with login limits, online without, offline with a slow hash, offline with a fast hash.
  • Colour-coded breakdown of every piece the attacker would recognise, masked while the password is hidden.
  • Specific weaknesses and suggestions in plain English, not just a score.
  • Show / Hide toggle, character-mix tags and length count; the first 64 characters are analysed.
  • No network access while checking, and no breach lookup by design.

Tips and good to know

  • The estimate is an informed guess, not a promise. It can’t know if the password is linked to you, such as your street, team or child’s name, which makes it weaker than shown.
  • A password that is strong but reused is still at risk: one leaky website exposes it everywhere you used it.
  • Online attacks are slow because websites limit attempts. The offline numbers matter when a site’s database is stolen, which is why length counts.
  • Avoid checking your real, current passwords on any site you don’t trust. Here it is safe because nothing leaves your device, but the habit matters.

Frequently asked questions

Is my password sent or saved anywhere?

No. The check runs in your browser and the password is never stored, logged or sent. The page makes no network request while you type, and closing the tab clears it.

Is it free? Are there limits?

It is free with no sign-up. Check as many passwords as you like; only the first 64 characters of a very long one are analysed.

Does it work on a phone or offline?

Yes. It works on iPhone, Android and computers, and once the page has loaded it keeps working without a connection.

Why does it call my password with symbols weak?

Because symbols in predictable places add little. Attackers try a common word with a capital at the front, look-alike swaps and a number or “!” on the end very early. Length and randomness matter far more than the number of character types.

Why can’t it check if my password has been leaked?

A leak check means sending part of the password’s fingerprint to an online service. We kept this tool fully offline so nothing about your password ever leaves your device.

What do the four crack times mean?

They are average times for different attackers: guessing on a website that allows about 100 tries an hour, a website with no limits, a stolen database protected by a slow hash such as bcrypt, and one using a fast hash such as MD5 with graphics cards.

Page last reviewed