Password strength checker
See how a password holds up and exactly what weakens it. The check happens on your device, nothing is sent anywhere.
Guide
How to use it
- Type a password, or a candidate you are considering. Use Hide if someone can see your screen.
- Read the verdict and the two crack times: a throttled online attack and a full offline one.
- Work through the advice lines, each names a specific weakness the checker found.
- Fix and re-test, or jump to the generator and replace it outright.
Examples
Worked examples
Passes most site rules, fails here: the core is the word PASSWORD with textbook substitutions, cracked in well under a second offline.
A dictionary word plus a year, the two most common patterns in leaked password lists, flagged as separate weaknesses by the checker.
14 random characters across all four sets: around 91 bits, centuries of offline cracking. This is what generated passwords buy you.
Method
How it works
The checker starts from the theoretical entropy of your password's length and character variety, then reduces it for patterns cracking tools try first: dictionary words (it un-does substitutions like @ for a and checks a 168,000 word list held in your browser), keyboard and number sequences, repeated runs and years. The result maps to a verdict and two crack time estimates.
It is an estimator, built by Wolds Cyber to be honest rather than flattering. The password never leaves the page: no network request carries it, nothing is stored and you can run the whole thing offline.
FAQ
Frequently asked questions
Is it safe to type my real password here?
The check runs entirely in your browser and the password is never sent, stored or logged. You can load the page, disconnect from the internet and it works identically. That said, the habit of typing passwords into random websites is worth being suspicious of, which is why this page explains exactly what it does.
How does the checker score a password?
It estimates entropy from length and character variety, then knocks it down for patterns attackers try first: dictionary words (including letter substitutions like @ for a), keyboard runs, repeated characters and years. The result is an estimate, not a guarantee.
The site I use accepted my password but this says weak. Who is right?
Site rules check composition, not guessability. P@ssw0rd1 passes most rules and would fall in seconds to any cracking list. Length and randomness matter more than ticking boxes.
What are the crack time assumptions?
Two scenarios: an online attack throttled to about 100 guesses per second, and an offline attack at ten billion guesses per second against a stolen database of fast hashes. Real numbers vary with how the site stores passwords.
Can this tell me if my password was in a data breach?
No, checking breach lists needs a lookup service, and this tool deliberately sends nothing. If you have reused a password anywhere, treat it as breached and change it. Have I Been Pwned is the reputable place to check an email address.
What actually makes a good password?
Length and randomness, unique per site. In practice: a password manager generating 16+ random characters, or a passphrase of four or more random words for things you must remember.
More tools