Password Strength
Estimate entropy and crack time, and see which patterns weaken a password.
Everything here runs entirely in your browser. Nothing you type, paste, or upload is ever sent to a server, logged, or stored.
About the Password Strength
Estimates how much genuine randomness a password you already have contains, and names the patterns that reduce it — dictionary words, keyboard runs, dates, repeated characters and common substitutions such as 3 for e.
When you would use it
- Deciding whether a password you have been using for years is worth replacing.
- Understanding why a password that looks complicated scores badly.
- Explaining to someone else what actually makes a password strong.
What it does not tell you
Crack time is a model, not a measurement. It assumes an attacker guessing offline at a stated rate, and the real number depends entirely on how the target stored the password — a fast unsalted hash and a properly tuned Argon2 differ by many orders of magnitude for the same password. Treat the estimate as a comparison between passwords, not as a promise about any one of them. Nothing you type is sent anywhere.