About
Type or paste a password and get an estimate from very weak to strong. It reads structure, which means length and the variety of characters, and it does that in the page rather than by asking a server anything.
How to use
Type into the field and the estimate updates as you go. Clear the field when you are done, and pair it with the generator when the answer is not what you hoped.
What the estimate is reading
Two things: how many characters there are, and how many different kinds. That is enough to catch the failures worth catching, which are passwords too short to survive an offline attack and passwords drawn from one narrow alphabet. It is a heuristic, not a simulation of a cracking run, and it is honest about being one.
The three risks the score cannot see
Reuse is the first and the largest: the same strong password on twelve sites is one breach away from being worthless everywhere. Leaks are the second, and they turn strong passwords into known ones. The third is what the site does with it, because a password stored with a weak hash offers little protection no matter how well you chose it. A score describes the string, not the situation.
Checking a password you actually use
The computation is local, which removes the network from the equation but not the room you are sitting in. A production credential on a screen behind you in an open office is exposed regardless of where the arithmetic happened. If you want to test a policy rather than a secret, type something with the same shape instead of the real value.
FAQ
Does the password I type get transmitted?
No. The estimate is computed in the page and there is no request carrying what you typed.
It says strong. Am I safe?
Only against guessing. A structurally strong password that you reused on a site which was breached is already compromised, and no structural score can see that.
Does it check whether my password has leaked?
It does not. Breach lookups need a query against a database, and that is a different kind of tool with a different privacy trade.
Why does a long ordinary phrase score better than a short messy one?
Because length wins. Four common words beat eight characters of punctuation on any measure that counts possibilities rather than appearances.
Related tools
- Security and generator tools
- Random Password Generator
Generate a password in the browser, nothing sent.
- SHA Hash Generator
SHA-1, SHA-256 and SHA-512 digests, computed locally.
- Random String Generator
Random tokens and test data, generated locally.
- Online 2FA Code Generator
Turn a Base32 secret into a 6 digit TOTP code.