P@ssw0rd!
Very weak: it's “password” with common substitutions, which attackers try first.
Estimate how strong a password is and how long it could take to crack — without it leaving your browser.
Checked in your browser — it is never sent or stored.
Type a password to check its strength.
Runs in your browser — nothing you enter is sent to a server.
Type a password to see an estimate of its strength. The checker counts the kinds of characters used (lowercase, uppercase, digits, symbols), treats repeated characters, sequences like abc or 123 and keyboard rows like qwerty as easy to guess, and recognizes the most common passwords even with l33t spellings or numbers added. The password never leaves your browser.
Crack times assume an attacker has a leaked password hash: about 10 billion guesses a second against a fast hash, or 10,000 a second against a slow one such as bcrypt.
bits ≈ effective length × log₂(character pool)
The pool is 26 for lowercase, +26 uppercase, +10 digits and +33 symbols; runs and repeats count as one character.
Very weak: it's “password” with common substitutions, which attackers try first.
16 characters from all 95 printable ASCII characters is about 105 bits — very strong.
It can't know how you chose the password. A passphrase of four common words scores highly by characters, but if the words came from a 2,048-word list it has only about 44 bits. Choose words at random, and use more of them.
Nothing is sent or stored, but good practice is to test a similar password rather than one you use.
Length and randomness: 16+ random characters or 5+ random words, unique to each site, kept in a password manager.
Create strong random passwords with the length and characters you choose, generated privately in your browser.
Security Tools
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or files, and check a checksum.
Security Tools
Encrypt and decrypt text with a passphrase using AES-256-GCM, entirely in your browser.
Security Tools