Password Strength Checker

Works offlineNothing is uploadedFree, no sign-up

ENTROPY—
CHARACTER POOL—
ONLINE ATTACK—
OFFLINE ATTACK (GPU)—

    Nothing typed here leaves this page. No network request is made at all.

    Type a password and read what it is worth: entropy in bits from its real character pool, the weaknesses crackers try first named one by one, and crack times for two honest scenarios — an online login that rate-limits, and an offline GPU rig grinding a stolen hash. Checked entirely in this tab; nothing you type is ever sent, stored or logged.

    Arithmetic first, folklore second

    The raw score is pure counting: which character classes appear fixes the pool, and length times log2(pool) is the bits. The honesty is in the discounts — a password on the common list is capped near nothing regardless of its decoration, keyboard runs and repeats and years subtract what crackers' rule engines recover for free.

    Crack times print the expected point — half the keyspace — under two named speeds, because a single 'time to crack' with no scenario is marketing. The gulf between the two columns is itself the lesson: what matters most is whether the hash ever leaks.

    Frequently asked questions

    Is it safe to type a real password here?

    The page makes no network requests — the checker is a few kilobytes of arithmetic in your tab, and you can watch the network panel stay empty while you type. Still, the careful habit is testing a candidate of the same shape rather than the exact password you already use.

    Why do the two crack times differ by a factor of a hundred million?

    Because the scenarios differ that much. An online attacker faces the server's rate limiting — order of a hundred guesses a second at best. An offline attacker holds the stolen hash file and asks a GPU rig, which tries tens of billions of fast hashes a second. The same password is safe in one story and gone in the other.

    Why does a long lowercase phrase beat Tr0ub4d!?

    Entropy is length times log2 of the pool, and length is the exponent's fuel: 25 lowercase letters carry about 117 raw bits, while 8 characters from the full keyboard carry about 52. Substituting 0 for o adds almost nothing — crackers try those mutations first. Long and memorable beats short and baroque.

    What should I actually do with a weak verdict?

    Not decorate — lengthen. Four random words beat any eight-character contortion; a password manager beats both by making every password random and unique. And enable two-factor auth where offered: it is the control that survives even a cracked password.

    Related tools