DevToolsForYou
Private by defaultRuns in your browser

Password strength checker

Type or paste any password to instantly see its entropy, strength rating, and how long it would take to crack at various attack speeds.

Quick samplesClick to test
Fair56.9 bits entropy
✓ Lowercase✗ Uppercase✓ Numbers✗ Symbols✗ 11 chars
Estimated crack time
Online attack (100/s)Centuries
Offline slow hash (1K/s)Centuries
Offline fast hash (1B/s)4 years
GPU cluster (100B/s)16 days
Strength Checker

About this tool

Most password strength meters are theatre. They score a password by counting character classes — one point for an uppercase letter, one for a digit, one for a symbol — which rates Passw0rd! as strong and correcthorsebatterystaple as weak, when an attacker would crack the first in seconds and the second essentially never. The meaningful measure is entropy: how many guesses an attacker needs, given they know exactly how the password was constructed. This checker estimates entropy in bits from the character set in use and the length, then translates that into estimated crack times at several attack speeds. The speeds matter as much as the number. An attacker throttled by a login form manages a handful of guesses per second; one with a stolen database of bcrypt hashes manages thousands per second per GPU; one with a database of unsalted SHA-256 hashes manages billions. The same password is unbreakable in the first scenario and gone by lunchtime in the third. Everything is computed in your browser — the password is never transmitted, logged, or stored.

No signup requiredRuns in your browserInstant results
How to use
  1. 1

    Type or paste any password into the input field.

  2. 2

    The tool instantly shows entropy (in bits), strength rating, and estimated crack times.

  3. 3

    Review the character composition breakdown to see which character types are present.

  4. 4

    Adjust your password based on the feedback to increase its strength.

Why use this tool?
  • →

    Audit existing passwords to find weak ones before they get compromised.

  • →

    Test a candidate password before setting it to ensure it meets your security bar.

  • →

    Understand the real-world impact of adding symbols or length to a password.

ExamplesInput → output

Weak password

Inputpassword123
Output~37 bits — Very Weak (cracked in seconds)

Mixed-case with symbols

InputP@ssw0rd!
Output~53 bits — Fair (hours at offline speed)

Long random password

InputX#9kLm$2pQr8!nVz
Output~105 bits — Strong (centuries at GPU speed)
Common errorsAnd how to fix them

A dictionary word with substitutions scores higher than expected

Cause: This checker estimates entropy from length and character-set composition. It does not run a dictionary or pattern analysis, so it cannot know that P@ssw0rd is among the first few thousand guesses any real cracker tries.

Fix: Treat the score as an upper bound. Any password built from a recognisable word, a name, a date, or a keyboard pattern is far weaker than its character composition suggests — generate a random one instead.

The estimated crack time seems wildly optimistic

Cause: Crack time depends entirely on how the password is stored on the far end, which is invisible from here. A password protected by Argon2id and one stored as an unsalted MD5 hash have crack times differing by many orders of magnitude.

Fix: Read the slowest attack scenario as the realistic one for a site you do not control. You cannot know a site's hashing choices, and breaches routinely reveal them to be worse than assumed.

Passphrases score lower than short complex passwords

Cause: A lowercase passphrase draws from a 26-character alphabet, so per-character entropy is low even though total entropy is high. Composition-based scoring underrates it.

Fix: Compare total entropy in bits, not the rating label. Four random words carry roughly 52 bits and are far easier to type and remember than an eight-character symbol soup of similar strength.

Frequently asked questionsCommon questions answered

These answers explain common strength checker tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.

How is entropy calculated?

Entropy is computed as length × log₂(pool size), where pool size is the number of distinct character types used (26 lowercase + 26 uppercase + 10 digits + 32 symbols).

How is crack time estimated?

Crack time is estimated by dividing the total number of combinations (2^entropy) by the attacker's guessing speed. Four speeds are shown: online attack (100/s), offline slow hash (1K/s), fast hash (1B/s), and GPU cluster (100B/s).

Is my password sent to a server?

No. The checker runs entirely in your browser. Your password is never transmitted or stored anywhere.

What entropy is considered strong?

Generally, 60+ bits is fair for low-risk accounts, 80+ bits is good, and 100+ bits is strong. For high-value accounts aim for 80 bits or more.