Security / 02

Password Strength Checker

Check how hard a password would be to guess, with an estimate of the time it would take to crack in four attack scenarios and advice on making it stronger, entirely on your device.

Password Strength Checker: The page uses zxcvbn, the open-source estimator first published by Dropbox, which looks for what attackers try first: common passwords, dictionary words and names, keyboard patterns such as qwerty, repeats, dates, and predictable substitutions like @ for a. It estimates the number of guesses needed and turns that into cracking times for an online attack and for a stolen password database. Runs 100% locally in your browser with zero server file uploads.

Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
Password strength checkerLocal processing

Runs entirely in your browser

Checked on this device only: the password is not sent anywhere, stored, or logged.

What makes a password hard to guess

Attackers do not try every combination in order; they start with leaked passwords, dictionaries, names, and the patterns people use to meet password rules, such as a capital first letter and a digit or symbol at the end. A password that follows those patterns falls early however complex it looks. Length and randomness are what hold up: four or more random words, or a long random string from a password generator, kept in a password manager.

Use a different password for every site. When one site is breached, attackers try the leaked email and password on others, so a reused password turns one breach into many, however strong it is.

How to read the estimate

The strength label follows zxcvbn's score from 0 to 4, and the times assume an attacker guessing in the order zxcvbn expects. They are estimates of guessability, not guarantees: a password shown as strong is still exposed if it is phished, reused, or already in a breach. For an account that matters, add two-factor authentication, which protects it even when the password is known.

How to use it

  1. Type or paste a password.
  2. Read its strength, the estimated time to crack it, and any warnings.
  3. Follow the suggestions, or generate a new password, and check again.

Privacy & limitations

The password is checked in your browser. It is never sent anywhere, stored, or recorded, and the page makes no network request with it. The word lists load once, before the check.

Related tools

Frequently asked questions

Is it safe to type my real password here?

The check runs entirely in your browser and the password is never sent or stored, which you can confirm in the browser's network tools. Even so, the safest habit is to test a password of the same pattern rather than one you use.

Why is a long passphrase stronger than a short complex password?

Each extra word multiplies the guesses needed. Four or more random, unrelated words are hard to guess and easy to remember, while a short password with a symbol swapped in follows patterns attackers try early.

Does it check whether my password has been leaked?

No. It estimates how guessable the password is, but does not look it up in lists of breached passwords, since that would mean sending information about it elsewhere. A password manager or a breach-alert service can tell you that.

What do the four attack scenarios mean?

Online attacks guess through a login page, slowly when the site limits attempts. Offline attacks work on a stolen copy of a site's password database: a site that stores passwords with a slow hash allows about ten thousand guesses a second, while a poorly protected one can allow billions.

Free tool · runs in your browser · no account required