Developer Security

Password strength checker

Strength Weak
0 bits of entropy · guessed instantly

Generated in your browser · never sent, never stored

Local · no network request on this page

This measures one thing: how many guesses an attacker would need if the password really were random. It reads the length and which character classes appear, and reports the entropy that combination could carry at best. Twelve characters of mixed case and digits is about 71 bits; eight of the same is about 48.

How to check a password

1 Type or paste the password. It stays in this page: there is no request to check against.
2 Read the bits figure and the estimated guessing time.
3 To judge a policy rather than a password, type any string that obeys it — the number depends on length and character classes, not on the characters themselves.
4 If it comes out weak, generate a replacement and store it in a password manager.

Be clear about the limitation, because most strength meters are not. This is an upper bound, not a score. "Password1!" contains four character classes across ten characters and scores as though it were random, when in reality it appears near the top of every cracking dictionary and falls in under a second. No meter that looks only at the characters can tell the difference. The number is meaningful for a password you generated randomly and misleading for one you invented — which is the strongest argument for not inventing them.

That same arithmetic is what answers "is twelve characters enough?", and it is worth using it that way. Because the calculation depends only on length and character classes, typing twelve characters that follow a rule tells you what the rule is worth: twelve of plain lowercase is about 56 bits, twelve with capitals and digits about 71, eight with capitals and digits about 48. Two policies that sound similar can be a factor of a million apart.

The composition rules themselves buy less than they cost. Allowing symbols grows the pool from 62 characters to about 95, which is roughly 0.6 extra bits per character; two more characters of length usually beat it. That is why current NIST guidance is to raise the minimum length, drop the mandatory capital and symbol, and check candidates against a list of known-breached passwords instead — the last of which is the part a character-counting meter can never do.

What people use it for

  • Judging a password policy by typing a string that follows it
  • Working out what a twelve-character minimum is worth in bits
  • Comparing two policies that sound alike and are not
  • Checking a password before it goes into a password manager
  • Seeing what four more characters are actually worth
  • Settling an argument about whether symbols matter

Questions

No. There is no network request on this page at all. The calculation is a few lines of arithmetic running locally.

NIST SP 800-63B rev 4, digital identity guidelinesMDN, Crypto.getRandomValues()
Was this tool any good?
Internal signal only · I use it to find the tools worth rebuilding