Password strength checker
Type or paste any password to instantly see its entropy, strength rating, and how long it would take to crack at various attack speeds.
About this tool
Most password strength meters are theatre. They score a password by counting character classes — one point for an uppercase letter, one for a digit, one for a symbol — which rates Passw0rd! as strong and correcthorsebatterystaple as weak, when an attacker would crack the first in seconds and the second essentially never. The meaningful measure is entropy: how many guesses an attacker needs, given they know exactly how the password was constructed. This checker estimates entropy in bits from the character set in use and the length, then translates that into estimated crack times at several attack speeds. The speeds matter as much as the number. An attacker throttled by a login form manages a handful of guesses per second; one with a stolen database of bcrypt hashes manages thousands per second per GPU; one with a database of unsalted SHA-256 hashes manages billions. The same password is unbreakable in the first scenario and gone by lunchtime in the third. Everything is computed in your browser — the password is never transmitted, logged, or stored.
- 1
Type or paste any password into the input field.
- 2
The tool instantly shows entropy (in bits), strength rating, and estimated crack times.
- 3
Review the character composition breakdown to see which character types are present.
- 4
Adjust your password based on the feedback to increase its strength.
Audit existing passwords to find weak ones before they get compromised.
Test a candidate password before setting it to ensure it meets your security bar.
Understand the real-world impact of adding symbols or length to a password.
Weak password
password123~37 bits — Very Weak (cracked in seconds)Mixed-case with symbols
P@ssw0rd!~53 bits — Fair (hours at offline speed)Long random password
X#9kLm$2pQr8!nVz~105 bits — Strong (centuries at GPU speed)A dictionary word with substitutions scores higher than expected
Cause: This checker estimates entropy from length and character-set composition. It does not run a dictionary or pattern analysis, so it cannot know that P@ssw0rd is among the first few thousand guesses any real cracker tries.
Fix: Treat the score as an upper bound. Any password built from a recognisable word, a name, a date, or a keyboard pattern is far weaker than its character composition suggests — generate a random one instead.
The estimated crack time seems wildly optimistic
Cause: Crack time depends entirely on how the password is stored on the far end, which is invisible from here. A password protected by Argon2id and one stored as an unsalted MD5 hash have crack times differing by many orders of magnitude.
Fix: Read the slowest attack scenario as the realistic one for a site you do not control. You cannot know a site's hashing choices, and breaches routinely reveal them to be worse than assumed.
Passphrases score lower than short complex passwords
Cause: A lowercase passphrase draws from a 26-character alphabet, so per-character entropy is low even though total entropy is high. Composition-based scoring underrates it.
Fix: Compare total entropy in bits, not the rating label. Four random words carry roughly 52 bits and are far easier to type and remember than an eight-character symbol soup of similar strength.
These answers explain common strength checker tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.
How is entropy calculated?
Entropy is computed as length × log₂(pool size), where pool size is the number of distinct character types used (26 lowercase + 26 uppercase + 10 digits + 32 symbols).
How is crack time estimated?
Crack time is estimated by dividing the total number of combinations (2^entropy) by the attacker's guessing speed. Four speeds are shown: online attack (100/s), offline slow hash (1K/s), fast hash (1B/s), and GPU cluster (100B/s).
Is my password sent to a server?
No. The checker runs entirely in your browser. Your password is never transmitted or stored anywhere.
What entropy is considered strong?
Generally, 60+ bits is fair for low-risk accounts, 80+ bits is good, and 100+ bits is strong. For high-value accounts aim for 80 bits or more.