Password Generator
Generate a strong random password with your browser's cryptographic generator. Set the length and character mix, then copy it. Nothing is sent anywhere.
Check how strong a password is and get an entropy estimate in bits, plus tips on what to add. The check runs on your device and sends nothing you type.
Updated
Your browser is preparing the tool. It runs 100% locally.
Type a password and the checker rates it from Very weak to Very strong, estimates its entropy in bits from its length and the character types it uses, and lists what would make it stronger. Your browser does all of this and never sends the password. One caveat: the entropy figure assumes a random password, so a real dictionary word scores higher here than it deserves.
As you type, the rating, the entropy estimate and a short to-do list (more length, mixed case, a number, a symbol) update live. Think of it as a quick coach for one password. It has no database of leaked ones.
It rewards what really enlarges an attacker's search space: length first, then variety. Watching the bit count climb as you add characters makes the trade-off easy to see.
Five checks each add a point: at least 8 characters, at least 14, both upper and lower case, a digit, and a symbol. The total from 0 to 5 maps onto the Very weak to Very strong scale.
Entropy is a separate estimate: length times log2 of the character pool. The pool counts 26 for lowercase, 26 for uppercase, 10 for digits and 32 for symbols, adding only the classes your password actually uses.
Nothing is fetched or sent. The page computes the rating and the entropy estimate from the characters you type. It makes no server call and does no breach-list lookup.
bits = length × log2(pool)
pool = 26 (lower) + 26 (upper) + 10 (digits) + 32 (symbols), counting only the classes used'password' (8 lowercase): 8 × log2(26) ≈ 38 bits, yet it tops the breached-word lists, so in practice it is near zero16 random chars, all classes (pool 94): 16 × log2(94) ≈ 105 bitsThe formula assumes randomness. It cannot see that 'password' or 'Pa$$w0rd' is a known pattern, so treat the bits as a ceiling, not a verdict.
The checker evaluates your password in your browser and makes no network request, so the password never leaves your device.
It stores and logs nothing. Clear the field or close the tab and the password is gone.
If you would rather not type a live account password anywhere, test a stand-in with the same length and character mix. The rating and bits will match.
| Checks | Length ≥8, length ≥14, upper+lower, a digit, a symbol |
|---|---|
| Rating | Very weak to Very strong (0 to 5) |
| Entropy | length × log2(pool), pool 26/26/10/32 |
| Breach check | Not performed |
| Pattern / dictionary detection | None |
| Input | Typed password, shown in plain text |
| Where it runs | In your browser; the password is never sent |
The main limit: it measures theoretical entropy, not how guessable a password really is. It can't tell that 'Summer2024!' follows a predictable pattern, so it over-rates passwords built from words, dates and keyboard runs. A high score is necessary but not sufficient.
It does not check your password against breach corpora, which NIST's guidance treats as the most valuable test. A password can read 'Strong' here and still sit on a public leak list, so pair this with a breach lookup.
The field shows your password in plain text so you can see what you typed. That is fine on your own screen, but take care in public or on a shared display.
Ratings use thresholds, so one extra character can bump the label a whole step. The entropy number moves more smoothly and is the better guide.
See roughly how strong a password is before you start using it somewhere.
Add characters and watch the bits jump. It shows quickly which changes make the biggest difference.
Type each one and compare the entropy to pick the stronger option.
Check whether a password clears a comfortable bit threshold before you save it.
To make a strong password, use the password generator. To catch breached or pattern-based passwords, use a checker built on a breach list or on zxcvbn-style pattern analysis. Treat this tool as a fast first look.
The bit count assumes a random password and the checker never looks at a breach list, so a high score here is a good sign, not proof. What you type stays in your browser.
Generate a strong random password with your browser's cryptographic generator. Set the length and character mix, then copy it. Nothing is sent anywhere.
Generate random whole numbers in any range, with an option for no repeats. The numbers come from the browser's cryptographic random source, not Math.random.
Compress an image to JPEG with a quality slider and watch the file size drop as you drag, in your browser.
Combine several PDFs into one file in the order you choose, without leaving your browser.
Count words, characters, sentences and paragraphs as you type, with reading and speaking time alongside.
Fill in your page title, description, keywords and author, and the tool writes a block of HTML head meta tags you can paste, with the title, description, viewport and robots tags included. The block updates as you type.
Run your check at the top of the page. What you enter stays on this device.