Password Strength Checker

Free Password Strength Checker

Check how strong an existing password is, with the exact reasons why — length, variety and common-password checks.

Last updated 3 September 2026

What's actually being checked

  • Length — the single biggest factor. Every extra character multiplies the number of possible passwords.
  • Character variety — mixing upper and lowercase, numbers and symbols increases the pool an attacker has to search.
  • Common-password matching — a check against well-known weak passwords, since real attacks try these before anything random.

The entropy figure is an estimate of guessing difficulty, in bits — each extra bit doubles the number of attempts a brute-force attack would need in the worst case.

Why length beats complexity

The intuition that a password needs a symbol, a number and a capital letter comes from rules written for eight-character passwords, and it has aged badly. An attacker guessing offline is running billions of attempts per second against a leaked hash, and every extra character multiplies the search space far more than swapping an a for an @ does.

Concretely: P@ssw0rd! satisfies almost every complexity rule ever written and falls in seconds, because the substitutions it uses are the first ones any cracking tool tries. Four unrelated words run together are longer, easier to remember and dramatically harder to guess. Current guidance from NIST reflects this — it recommends allowing long passphrases and dropping forced composition rules altogether.

What this checker can and cannot see

Strength here is estimated from structure: length, character variety, repeated runs, keyboard patterns, dates and recognisable words. That covers the way most weak passwords are actually weak. What it cannot know is whether your password has already appeared in a public breach — a genuinely random-looking string that leaked from another site is worth nothing, however strong it scores.

So treat a high score as one condition of three. The password also has to be unique to a single account, and anything genuinely valuable should have two-factor authentication on top. A password manager solves the first two at once, which is the real reason it is worth using.

Common questions

Is my password sent anywhere when I type it in?

No. Every check runs in your browser using JavaScript running on your own device. Nothing is transmitted, logged, or stored, and it's gone the moment you close or refresh the page.

What does the entropy number mean?

It's an estimate, in bits, of how many guesses an attacker would need in the worst case. Each extra bit doubles that number. Above roughly 80 bits is considered very strong for most purposes; below 40 is weak enough to be worth changing.

Why does a common password score low even if it's long?

Real attacks don't guess randomly — they try known common passwords and predictable patterns first. "password123456789" is technically long, but it would be among the first few thousand guesses an attacker tries, so length alone doesn't make it safe.

Is a long passphrase safer than a short complex password?

Usually, yes. Each additional character multiplies the number of possibilities an attacker has to work through, while predictable substitutions like @ for a are the first thing cracking tools try. Four unrelated words are both stronger and easier to remember than a short scrambled string.

Does a strong score mean the password has not been leaked?

No. This tool judges structure only. A password that scores well but was exposed in a breach on another site is already worthless, because attackers try known leaked passwords first. Uniqueness per account matters as much as strength.

Is my password sent anywhere when I test it here?

No. The analysis runs entirely in your browser using JavaScript. Nothing you type is transmitted, logged or stored, and closing the tab removes it. That said, the safest habit with any online checker is to test a pattern similar to your password rather than the live one.

The other tools