Password Strength Checker

Check how strong a password is and get an entropy estimate in bits, plus tips on what to add. The check runs on your device and sends nothing you type.

Updated

Password ToolsPopular● Free No upload Instant

Loading Password Strength Checker…

Your browser is preparing the tool. It runs 100% locally.

Quick answer

Type a password and the checker rates it from Very weak to Very strong, estimates its entropy in bits from its length and the character types it uses, and lists what would make it stronger. Your browser does all of this and never sends the password. One caveat: the entropy figure assumes a random password, so a real dictionary word scores higher here than it deserves.

What the Password Strength Checker does

As you type, the rating, the entropy estimate and a short to-do list (more length, mixed case, a number, a symbol) update live. Think of it as a quick coach for one password. It has no database of leaked ones.

It rewards what really enlarges an attacker's search space: length first, then variety. Watching the bit count climb as you add characters makes the trade-off easy to see.

How it works

Five checks each add a point: at least 8 characters, at least 14, both upper and lower case, a digit, and a symbol. The total from 0 to 5 maps onto the Very weak to Very strong scale.

Entropy is a separate estimate: length times log2 of the character pool. The pool counts 26 for lowercase, 26 for uppercase, 10 for digits and 32 for symbols, adding only the classes your password actually uses.

What it checks & how

Nothing is fetched or sent. The page computes the rating and the entropy estimate from the characters you type. It makes no server call and does no breach-list lookup.

  1. Step 1. Award a point if the password is at least 8 characters (and suggest more if not).
  2. Step 2. Award another point at 14 or more characters.
  3. Step 3. Award a point for having both uppercase and lowercase letters.
  4. Step 4. Award a point for containing a digit, and a point for a symbol.
  5. Step 5. Map the 0 to 5 total to a rating. Separately, compute entropy = length × log2(pool), with pool = 26/26/10/32 over the classes present.

Entropy estimate

bits = length × log2(pool) pool = 26 (lower) + 26 (upper) + 10 (digits) + 32 (symbols), counting only the classes used
Worked examples
'password' (8 lowercase): 8 × log2(26) ≈ 38 bits, yet it tops the breached-word lists, so in practice it is near zero
16 random chars, all classes (pool 94): 16 × log2(94) ≈ 105 bits

The formula assumes randomness. It cannot see that 'password' or 'Pa$$w0rd' is a known pattern, so treat the bits as a ceiling, not a verdict.

Privacy

The checker evaluates your password in your browser and makes no network request, so the password never leaves your device.

It stores and logs nothing. Clear the field or close the tab and the password is gone.

If you would rather not type a live account password anywhere, test a stand-in with the same length and character mix. The rating and bits will match.

Technical details

ChecksLength ≥8, length ≥14, upper+lower, a digit, a symbol
RatingVery weak to Very strong (0 to 5)
Entropylength × log2(pool), pool 26/26/10/32
Breach checkNot performed
Pattern / dictionary detectionNone
InputTyped password, shown in plain text
Where it runsIn your browser; the password is never sent

Standards and references

  • NIST SP 800-63B: recommends screening passwords against lists of breached and common values, and favouring length over forced complexity. This tool covers length and variety but does not check breach lists.
  • Entropy (bits): length × log2(pool), the usual measure of unpredictability. It only holds if the password is random.
  • Breach screening: comparing a candidate against known leaked passwords (for example via Have I Been Pwned) is the most useful real-world test, and this tool does not do it.

Accuracy and limits

The main limit: it measures theoretical entropy, not how guessable a password really is. It can't tell that 'Summer2024!' follows a predictable pattern, so it over-rates passwords built from words, dates and keyboard runs. A high score is necessary but not sufficient.

It does not check your password against breach corpora, which NIST's guidance treats as the most valuable test. A password can read 'Strong' here and still sit on a public leak list, so pair this with a breach lookup.

The field shows your password in plain text so you can see what you typed. That is fine on your own screen, but take care in public or on a shared display.

Ratings use thresholds, so one extra character can bump the label a whole step. The entropy number moves more smoothly and is the better guide.

Real-world uses

Sanity-checking a new password

See roughly how strong a password is before you start using it somewhere.

Teaching why length wins

Add characters and watch the bits jump. It shows quickly which changes make the biggest difference.

Comparing two candidates

Type each one and compare the entropy to pick the stronger option.

Deciding whether to lengthen

Check whether a password clears a comfortable bit threshold before you save it.

When it fits, and when it doesn't

Good for

  • A quick, private strength check
  • Understanding entropy in bits
  • Building better password habits
  • Comparing two passwords side by side

Not the best choice for

  • Proving a password isn't breached
  • Judging how guessable a patterned password really is
  • Creating a strong password from scratch

To make a strong password, use the password generator. To catch breached or pattern-based passwords, use a checker built on a breach list or on zxcvbn-style pattern analysis. Treat this tool as a fast first look.

Frequently asked questions

How is the strength rated?
Five checks each add a point: at least 8 characters, at least 14, both letter cases, a digit and a symbol. The 0 to 5 total maps to Very weak through Very strong.
What does the entropy number mean?
It estimates unpredictability in bits as length times log2 of the character pool. More length and more character types both raise it, and each extra bit doubles the guesses needed.
Why does a 'strong' password still feel guessable?
The entropy formula assumes the password is random. A patterned password like 'Summer2024!' has high nominal entropy, but a cracker that knows common patterns finds it fast, so the bits overstate its real strength.
Does it check whether my password was breached?
No, and that is a real gap. Breach screening, which compares a password against known leaked ones, is the most useful real test. A password can score well here and still be on a leak list, so check it separately.
Is my password sent anywhere?
No. Your browser computes both the rating and the entropy estimate, and the page neither transmits nor stores what you type.
Why is the password shown in plain text?
So you can confirm exactly what you typed, including spaces and symbols. Only your screen shows it, but be aware of who can see that screen in public.
How many bits is 'enough'?
As a rough guide, under about 50 bits is weak, 60 to 80 is reasonable for most accounts, and 100 or more is strong. A high-value account deserves more, and a breached password is weak at any bit count.
Does it detect dictionary words or keyboard patterns?
No. It counts character classes and length, not structure, so it won't flag 'qwerty' or 'letmein'. Tools based on zxcvbn do that kind of pattern analysis.
Why did adding one character jump the rating?
The rating uses thresholds (8 and 14 characters), so crossing one flips a whole point. The entropy figure changes gradually and is the smoother measure.
What's the difference between this and the password generator?
This tool grades a password you already have. The generator creates a new random one for you.
Should I type my real account password into any website?
Be cautious in general. This tool runs locally and sends nothing, but the safest habit is to test a password of the same length and make-up instead of your live one.
What symbol pool does the entropy use?
It assumes 32 for the symbol class, plus 26 each for upper and lower case and 10 for digits, summed over whichever classes appear in your password.

References

The bit count assumes a random password and the checker never looks at a breach list, so a high score here is a good sign, not proof. What you type stays in your browser.

PopularHot

Password Generator

Generate a strong random password with your browser's cryptographic generator. Set the length and character mix, then copy it. Nothing is sent anywhere.

PasswordOpen Tool
Popular

Random Number Generator

Generate random whole numbers in any range, with an option for no repeats. The numbers come from the browser's cryptographic random source, not Math.random.

PasswordOpen Tool
PopularHot

Image Compressor

Compress an image to JPEG with a quality slider and watch the file size drop as you drag, in your browser.

ImageOpen Tool
PopularHot

Merge PDF

Combine several PDFs into one file in the order you choose, without leaving your browser.

PDFOpen Tool
PopularHot

Word Counter

Count words, characters, sentences and paragraphs as you type, with reading and speaking time alongside.

TextOpen Tool
PopularHot

Meta Tag Generator

Fill in your page title, description, keywords and author, and the tool writes a block of HTML head meta tags you can paste, with the title, description, viewport and robots tags included. The block updates as you type.

SEOOpen Tool

Back to the Password Strength Checker

Run your check at the top of the page. What you enter stays on this device.