Password Strength Checker

Estimate how strong your password is — its entropy in bits, an offline crack-time estimate and what to fix. Everything runs in your browser: your password is never sent anywhere and nothing is stored.

Start typing above to see the strength, entropy and estimated crack time. The password stays on your device.

How the password strength checker works

  1. Type or paste a password into the box. Use the Show button to reveal what you typed.
  2. As you type, the tool measures the length, which character classes you use (lowercase, uppercase, digits, symbols) and estimates the entropy in bits.
  3. It penalises repeated characters and common passwords or patterns (like 123456, password or qwerty), then estimates how long an offline attacker would take to crack it.
  4. Read the suggestions to make the password stronger. Nothing you type is sent or saved.

Entropy is log2(poolSize^length). Crack time assumes about 10 billion guesses per second against a weak hash — treat it as a rough comparison, not a promise.

More PAYATE tools

Frequently asked questions

Is my password sent anywhere or stored?

No. All analysis runs entirely in your browser with plain JavaScript — the password is never sent to a server, never logged and never stored. Nothing leaves your device, so it is safe to test a real password here.

What is password entropy?

Entropy, measured in bits, estimates how unpredictable a password is. It is calculated as log2(poolSizelength), where poolSize is how many distinct character types you use (lowercase, uppercase, digits, symbols). Each extra bit doubles the number of guesses an attacker needs. Roughly: under 28 bits is very weak, 60+ bits is strong and 80+ bits is very strong.

How is the crack time estimated?

We assume a fast offline attack of about 10,000,000,000 (10 billion) guesses per second against a weak or unsalted hash, then divide the number of possible combinations by that rate. It is a rough guide, not a guarantee — a slow, well-salted hash takes far longer to crack, while a leaked or reused password can be cracked instantly.

Why is my long password still rated weak?

Length helps only when the password is unpredictable. Common passwords (like password1), dictionary words, keyboard runs (qwerty) and repeated characters are penalised because attackers try those first. A short random password can beat a long obvious one.

What makes a strong password?

Use length (aim for 14+ characters), mix lowercase, uppercase, digits and symbols, and avoid real words, names, dates and patterns. A random passphrase of several unrelated words, or output from a password manager, is both strong and easier to handle.

Should I reuse passwords across sites?

Never. If one site is breached, reused credentials let attackers into your other accounts. Use a unique password per site and a password manager to store them. This tool checks strength only — it cannot know whether a password has already been leaked.