Password Strength Checker

BUSINESS FREE

Free password strength checker. Score any password by entropy and estimated crack time. Runs entirely in your browser. No signup.

What the estimator measures

It scores a password by estimating its entropy — how many bits of randomness it contains — from its length and the variety of characters it uses. Entropy is the honest way to judge strength, because it explains why a long, varied password beats a short, complicated-looking one. Everything runs locally in your browser; the password is never sent anywhere or written to the URL.

How the calculation works

  • Character set size is summed from the character types present: lowercase adds 26, uppercase 26, digits 10, and symbols 32.
  • Entropy = length × log2(character set size). A longer password multiplies the result; a broader character set raises it.
  • Penalties cap the score for passwords on a common-password list, for a single repeated character, and for obvious sequences such as “abcdef…” or “qwerty…”.
  • A rough crack time is derived by assuming a billion guesses per second.

Worked examples

PasswordCharset sizeEntropyRatingCrack time
aaaaaaaa2612 bitsWeakseconds
password2628 bitsFairseconds
hunter2!6849 bitsGooddays
Tr0ub4dor&39472 bitsStrongcenturies

“password” has eight lowercase characters, which would give about 38 bits on length alone — but it sits on the common-password list, so the score is capped at 28. Being common matters more than being looks-complex.

Rating thresholds

RatingEntropyInterpretation
Weakunder 28 bitsTrivially cracked
Fair28–35 bitsFine only for low-value accounts
Good36–59 bitsAdequate for most uses
Strong60 bits and upResistant to offline attack

Common mistakes

  • Substituting symbols for length. “P@ssw0rd” is still a common word with obvious substitutions, and it is short. Length adds entropy multiplicatively.
  • Reusing one strong password everywhere. Strength on one site does not help if a breach on another exposes the same credentials.
  • Assuming a passphrase is weak. Three or four random words are long, easy to remember, and high-entropy — length wins.
  • Storing passwords in a note or spreadsheet. Use a password manager; it also removes the temptation to reuse.

Building a strong passphrase

Random words are easier to remember than random characters and can be just as strong, because entropy comes from the size of the word list and the number of words. With a 7,776-word list, each word contributes about 12.9 bits:

WordsEntropyRating
3~38.8 bitsGood
4~51.7 bitsGood
5~64.6 bitsStrong
6~77.5 bitsStrong

Five or six genuinely random words clear the strong threshold while staying memorable. The trick is that they must be random — a phrase you chose yourself carries far less entropy than it feels like, because it is drawn from language you already use.

Frequently asked questions

Is it safe to type my real password here?

The analysis is entirely client-side — nothing is transmitted and nothing is stored in the URL. Even so, the safest habit is to test a password of the same style and length rather than the exact one you use.

How long should a password be?

Twelve characters is a reasonable minimum for a mixed-character password, and longer is better. For a passphrase, four or more random words comfortably clears the strong threshold.

What is entropy in plain terms?

It is a measure of how many guesses an attacker would need. Each extra bit doubles the work, which is why adding length helps so much more than swapping a letter for a symbol.

Do password managers make strong passwords unnecessary?

No, but they make them practical. A manager lets you use long, unique passwords you never memorise. If you want to generate one, the random number generator can produce the raw values, and the logarithm calculator shows the base-2 maths behind entropy if you are curious.