Security Tools

Password Leak Checker

Find out whether a password has appeared in a data breach – without revealing it. Your browser computes the SHA-1 hash of the password and sends only the first five of its forty hex characters to the Pwned Passwords service by Have I Been Pwned. The service returns every known hash that starts with those five characters, and your browser compares them locally. The password and its full hash never leave the page, and nothing is logged or stored.

  • Encrypted connection
  • No sign-up
  • Free to use

Your password never leaves this page. The browser computes its SHA-1 hash and sends only the first 5 of 40 hex characters to the Have I Been Pwned Pwned Passwords service (k-anonymity). The service returns several hundred hash endings with that prefix, and the comparison happens here, in your browser. Nothing is logged or stored.

How to use Password Leak Checker

  1. Type or paste a password.
  2. Click Check password.
  3. See whether it appears in breaches and how often.
  4. Change any password that was found.

Password Leak Checker features

k-anonymity

Only a 5-character hash prefix is sent.

Local comparison

Matching happens in your browser.

Breach count

How often the password was seen.

Padding

Response size reveals nothing.

Strength hints

Length and common patterns.

No key needed

Free Pwned Passwords API.

When to use Password Leak Checker

  • Checking passwords before you use them.
  • Security awareness training.
  • Auditing a password policy.
  • Helping family members stay safe.

Password Leak Checker FAQ

Is it safe to type my password here?

Yes: the password is hashed in your browser and only the first five hex characters of the hash are sent. Millions of passwords share each prefix, so the service cannot know which one you checked.

What does “not found” mean?

The password is not in the Pwned Passwords collection. It can still be weak or guessable – use long, unique passwords.

Where does the data come from?

From Have I Been Pwned by Troy Hunt, which collects passwords from public data breaches (CC BY 4.0).

Should I change a found password?

Yes, everywhere you used it. Attackers try breached passwords first.

Why breached passwords are dangerous

Attackers use lists of breached passwords in “credential stuffing” attacks against other sites. A password that appears even once is no longer safe to use.

How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.

Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.

Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.

Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.

Other useful tools