–
Your password is analyzed by JavaScript on this page only. It is not sent, saved or logged. Still, avoid typing a password you use for important accounts into any website.
How this checker scores passwords
Simple checkers only count character types, so P@ssw0rd! looks "strong". Real attackers don't guess blindly: they start with leaked passwords, dictionary words with capital letters and number-for-letter swaps, names, years and keyboard patterns like qwerty. This checker looks for the same things and estimates how many guesses each part would take, then shows the time for a fast offline attack (10 billion guesses per second against a leaked password database).
What makes a password strong
- Length beats complexity. Every extra random character multiplies the work for an attacker.
- Randomness beats cleverness. Patterns you invent are patterns someone else already tried.
- Unique for every site. When one site leaks, reused passwords unlock your other accounts.
- Add two-factor authentication where you can — see our plain-English 2FA guide.
Frequently asked questions
- Is it safe to type my password here?
- The check runs entirely in your browser and nothing is transmitted. As a general habit, though, test similar passwords rather than the exact one protecting your email or bank.
- Why is my "complex" password rated weak?
- Probably because it is built from a word plus predictable changes — a capital first letter, a year, or 0 for o. Cracking tools try those variations first.
- What score should I aim for?
- "Strong" (60+ bits) for everyday accounts and "Very strong" (80+ bits) for your email and password manager. The passphrase generator reaches that with words you can remember.