How to use the password strength checker
- Type a password into the box and you get a score and tips as you type.
- Use the "Show" button to see what you typed.
- Use the checklist and tips to lengthen it or remove common patterns. If you need a new password, try the Password Generator.
How the score is calculated
First the character types used (lowercase, uppercase, digits, symbols, other scripts) give the number of possibilities per character, and multiplying by the length gives the entropy in bits. Each extra bit doubles the number of guesses required. Then any part that contains a sequence such as abc or 123, a keyboard run such as qwerty, a repeat such as aaa, a year such as 1990 or a common word is treated as not random and the entropy is cut sharply. A password that is on a list of the most common passwords, or is only a slight variation using characters like @ or 0, gets the lowest score. The final entropy is labeled very weak under 28 bits, weak under 36, fair under 60, strong under 80 and very strong above that, and the score is capped for passwords shorter than 8 characters.
How to build a safe password
- Make it long. Guidance from the US National Institute of Standards and Technology (NIST) also stresses length over complicated rules. At least 12 characters, ideally 16 or more.
- Use a different one for every site. Trying a password leaked from one site on other sites is a very common attack.
- Use a password manager. It remembers long random passwords for you.
- Turn on two-step verification. It protects the account even if the password leaks.
- Avoid personal information. Names, birthdays, phone numbers and pet names are easy to guess.
Common attack methods
A brute-force attack tries every possible combination, and a dictionary attack tries common words and variations first. Credential stuffing tries ID and password pairs leaked elsewhere on many sites. This checker imitates the first two in a simple estimate; it cannot tell whether a password has been leaked before.
Things to know
The score is a general estimate and does not guarantee real security. The same password can be more or less safe depending on how a service stores it and its security settings. If you suspect a password you use may have leaked elsewhere, change it right away.
FAQ
Is it safe to type a password here?
This tool does not send what you type to a server; it analyzes it only inside your browser. Still, browser extensions, screen sharing and similar paths could expose it, so do not enter a password you actually use. Test a similar structure instead.
Can I trust the "estimated time to guess"?
It is a simple estimate for a worst-case offline attack of 10 billion guesses per second. How a service stores passwords and whether it limits login attempts change the real time a lot, so treat it only as a rough comparison.
Do I need special characters?
Length matters most. A long phrase of four unrelated random words is often easier to remember and safer than a short complicated password. If a site has its own rules, follow them.
Privacy
The password you type is never sent to a server or stored; it is analyzed only inside your browser and disappears when you close the page.