Password Strength Checker

37 tools

Estimate strength locally, nothing leaves the tab.

Free to use with no account. JSON, passwords, hashes, 2FA and text tools run entirely in your browser.

Password Strength Checker

Estimate strength locally, nothing leaves the tab.

Free

-

About

Type or paste a password and get an estimate from very weak to strong. It reads structure, which means length and the variety of characters, and it does that in the page rather than by asking a server anything.

How to use

Type into the field and the estimate updates as you go. Clear the field when you are done, and pair it with the generator when the answer is not what you hoped.

What the estimate is reading

Two things: how many characters there are, and how many different kinds. That is enough to catch the failures worth catching, which are passwords too short to survive an offline attack and passwords drawn from one narrow alphabet. It is a heuristic, not a simulation of a cracking run, and it is honest about being one.

The three risks the score cannot see

Reuse is the first and the largest: the same strong password on twelve sites is one breach away from being worthless everywhere. Leaks are the second, and they turn strong passwords into known ones. The third is what the site does with it, because a password stored with a weak hash offers little protection no matter how well you chose it. A score describes the string, not the situation.

Checking a password you actually use

The computation is local, which removes the network from the equation but not the room you are sitting in. A production credential on a screen behind you in an open office is exposed regardless of where the arithmetic happened. If you want to test a policy rather than a secret, type something with the same shape instead of the real value.

FAQ

Does the password I type get transmitted?

No. The estimate is computed in the page and there is no request carrying what you typed.

It says strong. Am I safe?

Only against guessing. A structurally strong password that you reused on a site which was breached is already compromised, and no structural score can see that.

Does it check whether my password has leaked?

It does not. Breach lookups need a query against a database, and that is a different kind of tool with a different privacy trade.

Why does a long ordinary phrase score better than a short messy one?

Because length wins. Four common words beat eight characters of punctuation on any measure that counts possibilities rather than appearances.

Related tools

Password Strength Checker - Local Estimate, No Upload