Free online tools to generate, calculate,
convert, format, encode, and play.
 

Password Strength Checker

Analyze any password for strength, entropy, and estimated crack time. Everything runs locally in your browser - your password never leaves your device.


Strength: Enter a password Score: 0 / 100
Composition Analysis
Statistics
Estimated Crack Time
Issues Detected
Suggestions
    0
    out of 100
    Enter a password
    Strength Levels
    0 - 19 Very Weak
    20 - 39 Weak
    40 - 59 Fair
    60 - 79 Strong
    80 - 100 Very Strong

    How It Works

    This tool evaluates password strength by analyzing multiple factors including length, character diversity, entropy, and common patterns. Unlike simple checkers that only verify character types, this analyzer performs a detailed breakdown to help you understand exactly how strong your password is and why.

    Scoring Criteria

    • Length (up to 30 points): Longer passwords are exponentially harder to crack. Each character adds to the search space an attacker must cover.
    • Character Diversity (up to 25 points): Using uppercase, lowercase, numbers, and symbols increases the character set size, making brute-force attacks much harder.
    • Entropy (up to 25 points): Measures randomness based on character set size and length. Higher entropy means more possible combinations.
    • Penalties (up to -20 points): Common patterns like repeated characters, sequential runs (abc, 123), keyboard walks (qwerty), and dictionary words reduce the score.

    Entropy Explained

    Entropy is calculated as log2(charset_size ^ length), representing the number of bits of randomness. A password with 80+ bits of entropy is considered strong against modern brute-force attacks.

    Crack Time Estimates

    Crack time is estimated for different attack scenarios based on common hardware capabilities:

    • Online attack (100/sec): Throttled login attempts against a web service
    • Offline slow hash (10k/sec): Attacking bcrypt/scrypt hashes on a single machine
    • Offline fast hash (10B/sec): Attacking MD5/SHA hashes with GPU clusters
    • Massive cluster (1T/sec): State-level attacker with massive resources


    Embed This Util

    You can embed this util on your own site as a widget. Adding ?embed=1 to the URL loads a compact version with just the tool itself; no header, menu, or documentation. Paste this snippet into your HTML:

    
        

    Copy snippet Adjust the height to taste.



    Feedback

    Help us improve this page by providing feedback, and include your name/email if you want us to reach back. Thank you in advance.


    Share with