Skip to content
TNToolsNexus

Password strength checker

Estimate password strength honestly: entropy bits, an offline crack-time estimate, and specific pattern warnings — checked locally, never transmitted.

Checked entirely on your device — this page sends nothing, which you can verify in your browser's network tab.

Your password never leaves your browser — the analysis runs on your device.

Check a password’s strength without it ever leaving your device: an entropy estimate in bits, a worst-case offline crack time, and named warnings for the patterns cracking tools try first.

How to check a password

  1. Type or paste a password — analysis is instant, on every keystroke.
  2. Read the meter: the verdict bands run from under 28 bits (guessed in moments) past 90 bits (beyond practical brute force).
  3. Fix what the warnings name — each one flags a pattern that lets attackers skip most of the search space.
  4. Iterate until the estimate is where you want it, or generate a random one and skip the guesswork.

What the estimate actually measures

The checker computes entropy — the size of the search space implied by your password’s length and character variety — then discounts it for structure a cracking tool would exploit: dictionary-word starts, keyboard runs and sequences, repeated blocks, and trailing years. The crack time converts those bits into hours at 10 billion guesses per second, the ballpark of a serious offline rig working on a stolen password database. Real online login pages rate-limit to a few attempts per minute, so the shown figure is deliberately the attacker’s best day, not yours.

What no meter can tell you

An honest caveat: strength is one axis of password safety, not the whole of it. This tool cannot know whether the password already appears in a public breach corpus, or whether you use it on five other sites — the two failure modes that dominate real account takeovers. Treat the meter as a floor check, then pair every account with a unique password (a manager makes that free) and turn on two-factor authentication wherever it exists. A merely “fair” password that is unique and 2FA-backed beats a “very strong” one reused everywhere.

Private by design

Everything runs locally in your browser tab. The password is never transmitted, logged, or stored — open your browser’s Network tab while typing and watch nothing leave. Closing the tab erases every trace.

Last updated:

Frequently asked questions

Is it safe to type a real password here?
The analysis runs entirely in your browser — this page makes no network request with what you type, which you can verify live in your browser's developer tools (Network tab). That said, the habit of pasting real passwords into websites is worth avoiding; testing a candidate before you adopt it gives you the same answer with zero exposure.
How is the crack time calculated?
From the entropy estimate: we assume an offline attacker with dedicated hardware making 10 billion guesses per second, and report the time to search half the space — the statistical average until a hit. Online login forms are millions of times slower than this, so the number shown is the pessimistic case.
Why does my clever substitution still score weak?
Because cracking tools apply those same substitutions automatically — P@ssw0rd is tested nearly as early as password itself. The checker penalizes dictionary starts, sequences, repeats, and trailing years for exactly that reason; novelty that a machine can enumerate is not novelty.
Does a "very strong" rating guarantee safety?
No meter can promise that. Strength only measures resistance to guessing — it cannot see whether the password is reused across sites or already sitting in a breach dump. Unique-per-site and two-factor authentication matter as much as raw strength.
What score should I aim for?
Strong or very strong (roughly 60+ bits) for anything that matters, and very strong for email, banking, and your password manager — the accounts that unlock the others. A random 16-character mix or a four-word passphrase both get there easily.

Related tools

Password Generator

Cryptographically random passwords with length and character-type controls, a live strength meter, and a look-alike filter — generated on your device.

Hash Generator (SHA)

SHA-256, SHA-1, SHA-384, and SHA-512 of any text or file — with a paste-to-compare checksum verifier. Runs locally, nothing uploaded.

UUID Generator

Generate 1–100 cryptographically random version-4 UUIDs — uppercase and no-hyphen options, copy all in one click. Local, private.