Skip to content

Password strength checker

Type a password to see how long it would hold out against an attacker, and what makes it weak or strong.

Checked in your browser. Nothing you type is sent or stored.

The result appears as you type.

How it works

How attackers really guess passwords

When a website is breached, attackers get the stored password hashes and try guesses offline, billions per second. They don’t start with "aaaa". They start with what people actually use:

  1. Lists of millions of leaked passwords, such as 123456, password and qwerty.
  2. Dictionary words and names, with capitals, digits and symbols added in the usual places.
  3. Swaps like @ for a and 0 for o, which fool people more than they fool software.
  4. Years, dates, keyboard rows and repeated characters.

This checker looks for the same things. A password that avoids them and is long enough can only be cracked by trying every combination, which takes far too long.

Make it stronger

  • Let the password generator create a random one for you.
  • For passwords you type often, use the passphrase generator: four or more random words are strong and easy to remember.
  • Use a different password for every account, so one leak doesn’t unlock the others.

Frequently asked questions

Is it safe to type my password here?

The check runs entirely in your browser: the password is never sent, logged or stored. Still, it is good practice not to type real passwords into websites. Test a similar password instead, built the same way.

How is the strength calculated?

Attackers don’t try every combination; they start with common passwords, dictionary words, names, years and keyboard patterns. The checker splits your password into such pieces, estimates how many guesses each would take, and compares that with a plain brute-force attack. The weaker of the two counts. The time assumes an offline attack at 100 billion guesses per second.

Why is my long password rated weak?

Length only helps when it isn’t predictable. "Password2024!" is 13 characters, but it is a common password plus a year and a symbol, which is exactly what attackers try. Random characters, or several random words, give length that actually counts.

Does it check whether my password has been leaked?

No, because that requires asking an online database. Have I Been Pwned offers a password check that only sends the first five characters of a hash of your password, so the password itself never leaves your device.

What makes a password strong?

Length, randomness and being unique. Let a password manager generate and remember a random password for each account, or use a passphrase of four or more random words for the few you have to type.