Password Strength Tester
Estimate entropy & crack time
Evaluated entirely in your browser. Nothing is sent over the network or stored.
Assumes ~10 billion guesses/second (a fast offline GPU attack).
Checklist
- At least 12 characters
- Lowercase letters
- Uppercase letters
- Numbers
- Symbols
- No obvious patterns or common words
What Is the Password Strength Tester?
The Password Strength Tester estimates how strong a password is by calculating its entropy and approximating how long it would take to crack under realistic attack speeds. Type a password to get an instant, honest assessment — checked entirely in your browser and never transmitted — so you can decide whether a credential is strong enough before you rely on it.
Key Features
How Password Strength Is Measured
Strength is best expressed as entropy — the number of bits of unpredictability in a password. More entropy means exponentially more guesses to crack it. The tester estimates entropy from length and character variety, then translates it into an approximate crack time so the result is intuitive rather than abstract.
Why Crack Time Is an Estimate
Real crack time depends on the attacker’s hardware and method, so any figure is an approximation. The value here assumes realistic offline attack speeds to give a useful sense of scale — the difference between seconds, days, and centuries. Treat it as guidance for choosing a stronger password, not a precise guarantee.
Common Use Cases
- Checking whether an existing password is strong enough
- Comparing the strength of two passwords
- Teaching why length beats complexity
- Auditing credentials before reuse
Frequently Asked Questions
Is it safe to type my real password here?
Yes. The password is analyzed entirely in your browser and is never sent to or stored on any server. That said, as a habit, avoid typing currently active passwords into any website.
What is password entropy?
Entropy measures unpredictability in bits. Each additional bit doubles the number of guesses needed to crack the password, so higher entropy means dramatically stronger protection against brute-force attacks.
Why does length matter more than symbols?
Adding length increases the number of possible combinations far faster than swapping in a few symbols. A long passphrase usually beats a short password full of special characters.
How accurate is the crack-time estimate?
It is an informed approximation based on realistic attack speeds. Actual time varies with the attacker’s hardware and method, so use it to compare relative strength rather than as an exact figure.
What makes a password weak?
Short length, dictionary words, predictable patterns, keyboard sequences, and personal information all weaken a password. The tester flags these so you can avoid them.
Want to browse more security and privacy tools?
Explore all tools