Security Tools

Password Strength Checker

Find out how hard a password would be to guess. The checker looks for the patterns attackers try first, such as common passwords, words, keyboard walks like “qwerty”, sequences, repeated characters, years and your own name, estimates the number of guesses needed, and shows how long that would take in four realistic attack scenarios. Everything runs on your device: the password is never sent, saved or logged.

  • Runs in your browser
  • No sign-up
  • Free to use

Checked on this device only. The password is never sent, saved or logged.

Passwords built from your own details are easier to guess for someone who knows you.

Strength
–
    Estimated time to guess
    Attack scenarioEstimated time
    How the password was analysed
    PartRecognised asBits

    How to use Password Strength Checker

    1. Type or paste a password. Use Show if you want to see it.
    2. Optionally add your name or e-mail to check for personal details.
    3. Read the strength, the estimated guessing time and the advice.
    4. Look at the breakdown to see which parts make it weak.

    Password Strength Checker features

    Pattern detection

    Common passwords, dictionary words, keyboard patterns, sequences, repeats, years and dates.

    Leetspeak aware

    Recognises “P@ssw0rd” as “password” with substitutions.

    Realistic estimate

    Counts guesses for the cheapest way to describe the password, not just its length.

    Attack scenarios

    Online with and without rate limiting, offline with slow and fast hashes.

    Personal details

    Flags your own name or e-mail inside the password.

    Private by design

    No network requests, no storage; the field is cleared when you leave.

    When to use Password Strength Checker

    • Checking whether an existing password should be changed.
    • Learning why “Summer2024!” is weak despite meeting the usual rules.
    • Testing a passphrase before using it for a password manager.
    • Teaching password hygiene in training sessions.

    Password Strength Checker FAQ

    Is my password sent anywhere?

    No. The check runs entirely in your browser. Nothing is transmitted to this site or any other service, nothing is stored, and the field is cleared when you leave the page. You can disconnect from the internet and the checker still works.

    Why is my password weak when it has symbols and numbers?

    Attackers do not guess character by character. They try common passwords, words, names and dates first, with predictable substitutions such as @ for a and a year or ! at the end. “P@ssw0rd2024!” follows exactly those patterns.

    What do the attack scenarios mean?

    Online attacks guess through a login page, which is slow and often rate-limited. Offline attacks work on a stolen database of password hashes: slow hashes such as bcrypt allow thousands of guesses per second, fast ones billions.

    Does it check whether my password has been in a data breach?

    No. Breach checks require contacting an external service, and this tool deliberately sends nothing. It does recognise the most common breached passwords from a built-in list.

    What makes a strong password?

    Length and unpredictability. A random string of 16 characters from a password manager, or a passphrase of five or more random words, resists guessing. Use a different one for every account.

    How accurate is the estimate?

    It is an estimate of guessing difficulty based on known patterns, similar in approach to the zxcvbn estimator. Real attackers may know more about you, so treat the result as an upper bound on strength.

    How attackers really guess passwords

    Password rules such as “one capital, one number, one symbol” were meant to make passwords stronger, but they mostly produced predictable ones: a word, a capital at the start, a year and an exclamation mark at the end. Attackers know these habits. Their tools try the most common passwords first, then dictionary words with typical capitalisation and substitutions, then keyboard walks, dates and names, long before they fall back to trying random characters.

    This checker estimates strength the same way. It looks for every known pattern in the password and finds the cheapest combination of patterns that describes it completely. Each pattern costs a number of bits, the logarithm of how many guesses it would take to hit; random characters cost the most, a top-ten password almost nothing. The total gives an estimate of the guesses an informed attacker would need.

    Guesses become time through the speed of the attack. Through a login page, an attacker might manage a few guesses per second or fewer, and well-run sites limit attempts. If a site’s password database is stolen, attackers can guess offline as fast as their hardware allows: thousands of guesses per second against a slow hash such as bcrypt or Argon2, billions against an unsalted fast hash. A good password must survive the worst case.

    The practical answer is to stop creating passwords by hand. A password manager can generate and remember a long random password for every site, and you need to memorise only one strong passphrase to unlock it. Turn on two-factor authentication wherever it is offered: it protects the account even when a password leaks.

    Other useful tools