Platform
Password Strength
Check password entropy, estimated crack times, and get actionable hints to harden your password.
Enter Password
Your password is processed locally in the browser — never sent anywhere.
Very Weak
0.0 bits0140+ bits
Entropy is estimated as
length × log₂(charset).Estimated Crack Times
How long a brute-force/dictionary attack could take, under different assumptions.
Online (10/sec)
0.1 secOnline Fast (100/sec)
0.0 secOffline (slow hash ~100k/sec)
0.0 secOffline (fast hash ~10B/sec)
0.0 secNation-state (1T/sec)
0.0 secReality varies with attacker hardware, hashing algorithm, rate limits, 2FA, and whether the password appears in breach dumps.
Suggestions update as you type.
Start typing above to see tailored hints.
Best practices
- Use 14–20+ characters; passphrases are great (four+ random words).
- Mix lower/upper, digits, and symbols — but avoid predictable substitutions (e.g.,
a→@). - Avoid dictionary words, names, dates, keyboard patterns, or company/product names.
- Never reuse passwords; enable 2FA wherever possible.
- Prefer a password manager to generate & store unique passwords.
Batch Test (Optional)
One candidate per line — we’ll score them quickly (no data leaves your browser).
Add lines above to see results.