Password Strength Checker
Type a password and read what it is worth: entropy in bits from its real character pool, the weaknesses crackers try first named one by one, and crack times for two honest scenarios — an online login that rate-limits, and an offline GPU rig grinding a stolen hash. Checked entirely in this tab; nothing you type is ever sent, stored or logged.
Arithmetic first, folklore second
The raw score is pure counting: which character classes appear fixes the pool, and length times log2(pool) is the bits. The honesty is in the discounts — a password on the common list is capped near nothing regardless of its decoration, keyboard runs and repeats and years subtract what crackers' rule engines recover for free.
Crack times print the expected point — half the keyspace — under two named speeds, because a single 'time to crack' with no scenario is marketing. The gulf between the two columns is itself the lesson: what matters most is whether the hash ever leaks.
Frequently asked questions
Is it safe to type a real password here?
The page makes no network requests — the checker is a few kilobytes of arithmetic in your tab, and you can watch the network panel stay empty while you type. Still, the careful habit is testing a candidate of the same shape rather than the exact password you already use.
Why do the two crack times differ by a factor of a hundred million?
Because the scenarios differ that much. An online attacker faces the server's rate limiting — order of a hundred guesses a second at best. An offline attacker holds the stolen hash file and asks a GPU rig, which tries tens of billions of fast hashes a second. The same password is safe in one story and gone in the other.
Why does a long lowercase phrase beat Tr0ub4d!?
Entropy is length times log2 of the pool, and length is the exponent's fuel: 25 lowercase letters carry about 117 raw bits, while 8 characters from the full keyboard carry about 52. Substituting 0 for o adds almost nothing — crackers try those mutations first. Long and memorable beats short and baroque.
What should I actually do with a weak verdict?
Not decorate — lengthen. Four random words beat any eight-character contortion; a password manager beats both by making every password random and unique. And enable two-factor auth where offered: it is the control that survives even a cracked password.
Related tools
- Diagram & Flowchart MakerDraw flowcharts and diagrams, connect the boxes with arrows that route themselves, and let it arrange the whole thing. Exports SVG. Nothing is uploaded.
- Password GeneratorGenerate strong random passwords using your browser's cryptographic RNG, with a live strength estimate.
- HTML Entity EncoderEncode text for HTML or decode entities back — the five markup breakers, named Latin-1 and symbol sets, numeric references up to emoji. Decodes exactly once.