Skip to the tool

Password strength checker

See how a password holds up and exactly what weakens it. The check happens on your device, nothing is sent anywhere.

Guide

How to use it

  1. Type a password, or a candidate you are considering. Use Hide if someone can see your screen.
  2. Read the verdict and the two crack times: a throttled online attack and a full offline one.
  3. Work through the advice lines, each names a specific weakness the checker found.
  4. Fix and re-test, or jump to the generator and replace it outright.

Examples

Worked examples

P@ssw0rd1

Passes most site rules, fails here: the core is the word PASSWORD with textbook substitutions, cracked in well under a second offline.

chelsea2008

A dictionary word plus a year, the two most common patterns in leaked password lists, flagged as separate weaknesses by the checker.

k7#Vq!2m-Xw9$e

14 random characters across all four sets: around 91 bits, centuries of offline cracking. This is what generated passwords buy you.

Method

How it works

The checker starts from the theoretical entropy of your password's length and character variety, then reduces it for patterns cracking tools try first: dictionary words (it un-does substitutions like @ for a and checks a 168,000 word list held in your browser), keyboard and number sequences, repeated runs and years. The result maps to a verdict and two crack time estimates.

It is an estimator, built by Wolds Cyber to be honest rather than flattering. The password never leaves the page: no network request carries it, nothing is stored and you can run the whole thing offline.

FAQ

Frequently asked questions

Is it safe to type my real password here?

The check runs entirely in your browser and the password is never sent, stored or logged. You can load the page, disconnect from the internet and it works identically. That said, the habit of typing passwords into random websites is worth being suspicious of, which is why this page explains exactly what it does.

How does the checker score a password?

It estimates entropy from length and character variety, then knocks it down for patterns attackers try first: dictionary words (including letter substitutions like @ for a), keyboard runs, repeated characters and years. The result is an estimate, not a guarantee.

The site I use accepted my password but this says weak. Who is right?

Site rules check composition, not guessability. P@ssw0rd1 passes most rules and would fall in seconds to any cracking list. Length and randomness matter more than ticking boxes.

What are the crack time assumptions?

Two scenarios: an online attack throttled to about 100 guesses per second, and an offline attack at ten billion guesses per second against a stolen database of fast hashes. Real numbers vary with how the site stores passwords.

Can this tell me if my password was in a data breach?

No, checking breach lists needs a lookup service, and this tool deliberately sends nothing. If you have reused a password anywhere, treat it as breached and change it. Have I Been Pwned is the reputable place to check an email address.

What actually makes a good password?

Length and randomness, unique per site. In practice: a password manager generating 16+ random characters, or a passphrase of four or more random words for things you must remember.

More tools

Related tools

Password generatorReplace a weak password with a properly random one. Passphrase generatorRandom words for passwords you have to remember. Memorable password generatorPronounceable passwords for WiFi keys and spoken use.
Skip to the tool

Password strength checker

See how a password holds up and exactly what weakens it. The check happens on your device, nothing is sent anywhere.

Checked on your device only. It is never sent, stored or logged.

Everything runs in your browser using its built-in cryptographic randomness. Nothing you generate or type is sent to a server.

Guide

How to use it

  1. Type a password, or a candidate you are considering. Use Hide if someone can see your screen.
  2. Read the verdict and the two crack times: a throttled online attack and a full offline one.
  3. Work through the advice lines, each names a specific weakness the checker found.
  4. Fix and re-test, or jump to the generator and replace it outright.

Examples

Worked examples

P@ssw0rd1

Passes most site rules, fails here: the core is the word PASSWORD with textbook substitutions, cracked in well under a second offline.

chelsea2008

A dictionary word plus a year, the two most common patterns in leaked password lists, flagged as separate weaknesses by the checker.

k7#Vq!2m-Xw9$e

14 random characters across all four sets: around 91 bits, centuries of offline cracking. This is what generated passwords buy you.

Method

How it works

The checker starts from the theoretical entropy of your password's length and character variety, then reduces it for patterns cracking tools try first: dictionary words (it un-does substitutions like @ for a and checks a 168,000 word list held in your browser), keyboard and number sequences, repeated runs and years. The result maps to a verdict and two crack time estimates.

It is an estimator, built by Wolds Cyber to be honest rather than flattering. The password never leaves the page: no network request carries it, nothing is stored and you can run the whole thing offline.

FAQ

Frequently asked questions

Is it safe to type my real password here?

The check runs entirely in your browser and the password is never sent, stored or logged. You can load the page, disconnect from the internet and it works identically. That said, the habit of typing passwords into random websites is worth being suspicious of, which is why this page explains exactly what it does.

How does the checker score a password?

It estimates entropy from length and character variety, then knocks it down for patterns attackers try first: dictionary words (including letter substitutions like @ for a), keyboard runs, repeated characters and years. The result is an estimate, not a guarantee.

The site I use accepted my password but this says weak. Who is right?

Site rules check composition, not guessability. P@ssw0rd1 passes most rules and would fall in seconds to any cracking list. Length and randomness matter more than ticking boxes.

What are the crack time assumptions?

Two scenarios: an online attack throttled to about 100 guesses per second, and an offline attack at ten billion guesses per second against a stolen database of fast hashes. Real numbers vary with how the site stores passwords.

Can this tell me if my password was in a data breach?

No, checking breach lists needs a lookup service, and this tool deliberately sends nothing. If you have reused a password anywhere, treat it as breached and change it. Have I Been Pwned is the reputable place to check an email address.

What actually makes a good password?

Length and randomness, unique per site. In practice: a password manager generating 16+ random characters, or a passphrase of four or more random words for things you must remember.

More tools

Related tools