Password Strength Checker
Type or paste a password to see an estimate of its strength in bits, how long an attacker would need on average at several guess rates, and whether it meets the NIST length minimums. The check runs in your browser and nothing is sent anywhere.
The check runs in your browser and nothing is sent anywhere. Even so, a good habit is to test a password that is similar to your real one, not the real one.
Related Tools
[3 suggestions]Password Generator
Generate cryptographically secure random passwords with custom length and character sets.
Developer & WebHash Generator (MD5, SHA-1, SHA-256, SHA-512)
Generate MD5, SHA-1, SHA-256, and SHA-512 cryptographic hashes live from any text using the native Web Crypto API.
Developer & WebUUID Generator
Generate cryptographically random UUID v4 identifiers instantly, one or in bulk.
Developer & WebAbout the Password Strength Checker
The estimate is the number of characters that count, multiplied by the log base 2 of the symbol pool. The pool adds 26 for lowercase letters, 26 for capitals, 10 for digits, 33 for ASCII symbols and spaces, and 100 for any other character. Characters that repeat the one before them, continue a sequence such as abc or 123, or follow a keyboard run such as qwerty, are not counted as new. A password that is, or is a light variation of, one of about 150 very common passwords is rated as guessable at once, using a short built-in list rather than a breach database. The result is an upper bound that holds only for a randomly generated password, because names, dates and phrases a person picked are easier to guess than their length suggests. Average guess time is half the search space divided by an assumed guess rate. The rates shown, 100 billion a second and 1 million a second, are comparisons and not measurements, and the online line shows the chance of success before a lockout after 100 failed attempts, the limit in NIST SP 800-63B-4. The tool also checks the NIST minimums of 15 characters when a password is the only factor and 8 when a second factor is used. NIST does not ask for a mix of character types, so this tool does not either: a long password of one type can score well. Text made only of separate words, such as a passphrase, is scored as that many words picked at random from a 7,776-word list, about 12.9 bits a word, which is the best case for a phrase. Words you chose yourself, such as a quote, are much weaker, and a long run of letters with no spaces can be a word or phrase rather than random letters, so the tool warns about both. Use a password manager to create and store unique passwords.
Is it safe to type my real password here?▾
The check runs entirely in your browser and nothing is sent to a server. Even so, it is a good habit to test a password that is similar to your real one, and never to type a real password into a site you do not trust.
How is password strength measured in bits?▾
Each bit doubles the number of guesses an attacker needs. A password of n random characters from a pool of p symbols has n times log base 2 of p bits. The figure is an upper bound that only holds for a randomly generated password.
Why does a long lowercase password score well?▾
Because length matters more than variety. Sixteen random lowercase letters have about 75 bits, more than an 8-character password drawn from every key on the keyboard. NIST also says sites should not require mixed character types.
Does this check whether my password was in a breach?▾
No. It only compares against a short built-in list of about 150 very common passwords. To check for breaches, use a dedicated breach-checking service or your password manager.