Check a password’s strength without it ever leaving your device: an entropy estimate in bits, a worst-case offline crack time, and named warnings for the patterns cracking tools try first.
How to check a password
- Type or paste a password — analysis is instant, on every keystroke.
- Read the meter: the verdict bands run from under 28 bits (guessed in moments) past 90 bits (beyond practical brute force).
- Fix what the warnings name — each one flags a pattern that lets attackers skip most of the search space.
- Iterate until the estimate is where you want it, or generate a random one and skip the guesswork.
What the estimate actually measures
The checker computes entropy — the size of the search space implied by your password’s length and character variety — then discounts it for structure a cracking tool would exploit: dictionary-word starts, keyboard runs and sequences, repeated blocks, and trailing years. The crack time converts those bits into hours at 10 billion guesses per second, the ballpark of a serious offline rig working on a stolen password database. Real online login pages rate-limit to a few attempts per minute, so the shown figure is deliberately the attacker’s best day, not yours.
What no meter can tell you
An honest caveat: strength is one axis of password safety, not the whole of it. This tool cannot know whether the password already appears in a public breach corpus, or whether you use it on five other sites — the two failure modes that dominate real account takeovers. Treat the meter as a floor check, then pair every account with a unique password (a manager makes that free) and turn on two-factor authentication wherever it exists. A merely “fair” password that is unique and 2FA-backed beats a “very strong” one reused everywhere.
Private by design
Everything runs locally in your browser tab. The password is never transmitted, logged, or stored — open your browser’s Network tab while typing and watch nothing leave. Closing the tab erases every trace.