Password Strength Checker
Estimate how strong a password is — checked entirely in your browser, never sent anywhere.
How to use
- Type or paste a password.
- The bar and label show its estimated strength.
- Aim for 'Strong' or better — longer is the biggest factor.
How the Password Strength Checker works
Estimates how strong a password is by measuring its entropy in bits, rather than applying the arbitrary 'must contain a symbol' rules most sites use.
It infers the character pool from what the password contains — 26 for lowercase, 26 for uppercase, 10 for digits, 32 for symbols — then multiplies the length by the log base 2 of that pool size to get entropy in bits.
bits = length × log₂(pool size)
Worked example
'Tr0ub4dor&3' is 11 characters over a 94-character pool, about 72 bits. The passphrase 'correct horse battery staple' is far longer and scores higher despite using only lowercase and spaces.
Things worth knowing
- Bands used here: under 40 bits weak, 40–59 fair, 60–79 strong, 80+ very strong.
- Entropy assumes randomness. A dictionary word with predictable substitutions scores well on this measure but falls quickly to a real cracking attack.
- Your password is analysed entirely in the browser and is never sent anywhere.
Frequently asked questions
Is my password sent anywhere?
No — it's evaluated entirely in your browser and never transmitted.
What makes a strong password?
Length above all, plus a mix of upper and lower case, numbers and symbols.
Why does my password score badly despite having symbols?
Because length dominates. Adding two characters raises entropy more than swapping one letter for a symbol.
Is this a real crack-time estimate?
No. It measures theoretical entropy. Real attackers use dictionaries and known-password lists, against which common patterns fall far faster than the bit count suggests.