GeneratePass
ANALYZE PASSWORD STRENGTH

Password Strength Checker

Analyze your credentials' resistance to modern GPU dictionary-cracking scripts.

Empty 0 Bits

Diagnostics & Suggestions

  • ✕ Input password to begin checks.

Est. Offline Crack Time

Fast Hashing Rig (RTX 4090 pool) Instant
Consumer Laptop (CPU solver) Instant

Calculated assuming a standard hash brute-force index rate of 100 billion checks per second (GPU rig) and 10 million checks per second (CPU).

Decision Guide

When Should I Check Password Strength?

Before setting a new password

Test your chosen password before committing to it. If it rates "Weak" or "Dangerous," generate a stronger one instead.

After hearing about a data breach

If a service you use was breached, check whether your password is strong enough to resist offline cracking. Weak passwords must be changed immediately.

Auditing your existing passwords

Check your current passwords one by one. Replace any that rate below "Moderate" with generated passwords stored in a password manager.

Creating a password policy

Use the entropy ratings to set minimum strength requirements for your team or organization.

Important Warning

When Should I NOT Rely on This?

To check if a password is in a breach

This tool checks structural strength only. Use the Breach Checker to verify against known data breaches.

To verify password uniqueness across accounts

A password can score "Perfect" here but still be unsafe if reused. Only a password manager tracks uniqueness.

To generate a new password

This tool analyzes, it does not generate. Use the Password Generator or Passphrase Generator to create new credentials.

Next Steps

What to Do After Checking?

1
If "Dangerous" or "Weak" — Generate a new 16+ character password immediately and update all accounts using it.
2
If "Moderate" — Consider strengthening by adding length. A few extra characters can move you to "Strong."
3
Check for breaches — Use the Breach Checker to see if this password has appeared in any known data leaks.
4
Enable 2FA — Regardless of strength, add two-factor authentication wherever available.
Real-World Scenario

You just heard your email provider was breached

1. Enter your current email password above

2. If it shows "Dangerous" or "Weak" — change it immediately

3. Generate a new 16+ character password with the Password Generator

4. Check the new password here to confirm it rates "Strong" or better

5. Use the Breach Checker to verify the old password appears in breach databases

6. Enable 2FA on your email account

Understanding Your Results

What the Strength Rating Means

The strength meter combines multiple factors — length, character diversity, dictionary presence, and pattern analysis — into a single rating. Here is what each level actually means:

Dangerous (0–35 bits)

Crackable in seconds to minutes. Common passwords, short strings, or dictionary words fall here. Change immediately.

Weak (35–55 bits)

Crackable in hours to days with GPU rigs. Typical 8–10 character passwords with moderate complexity. Not safe for important accounts.

Moderate (55–75 bits)

Resists casual attacks but may fall to dedicated cracking. Acceptable for low-value accounts with 2FA enabled.

Strong (75–95 bits)

Resists most offline attacks. Suitable for email, banking, and password manager master passwords.

Perfect (95+ bits)

Computationally infeasible to crack with current technology. Ideal for encryption keys and high-security credentials.

Important: This is an estimate. Actual crack time depends on the hash algorithm, attacker hardware, and whether the password appears in breach databases. A "Strong" rating does not guarantee security if the password is reused or appears in a breach.

NIST Recommendations

Lengthen, don't overcomplicate.

Modern security audits show that password length is much more protective than swapping letters with numbers (e.g. replacing 'e' with '3'). A 16-character lowercase sentence is significantly harder to break than an 8-character complex password containing symbols, due to exponential character choices.

Decoding the Results

What the Results Mean

Entropy: The Randomness Score

The "Bits" value shown below the strength bar is your password's entropy — a measure of randomness in bits. Each bit doubles the number of possible combinations an attacker must try. A password with 50 bits of entropy has roughly 250 (over one quadrillion) possible combinations, while 80 bits means 280 possibilities. Higher entropy directly translates to longer crack times.

Strength Ratings Explained

Each rating reflects both entropy and pattern analysis:

  • Very Weak / Dangerous — Under 35 bits. Crackable in seconds to minutes by any attacker.
  • Weak — 35–55 bits. Falls in hours to days with a single GPU rig.
  • Moderate — 55–75 bits. Survives casual attacks but yields to a dedicated cracking setup in days to weeks.
  • Strong — 75–95 bits. Resists most offline attacks. Practical for email, banking, and password managers.
  • Very Strong / Perfect — 95+ bits. Computationally infeasible to crack with current technology.

How Crack Times Are Estimated

The tool shows two crack-time scenarios:

  • GPU Rig (RTX 4090 pool) — Simulates an offline attack at ~100 billion hash guesses per second. This represents what a well-funded attacker could achieve with modern hardware.
  • CPU Laptop — Simulates a single consumer machine at ~10 million guesses per second. This is a more realistic speed for a hobbyist attacker.

Online attacks (guessing a password on a live website) are far slower — typically 1–100 attempts per second — because servers enforce delays and lockouts. The offline times shown are the worst-case scenario for leaked hash databases.

Why This Goes Beyond Character Counts

A simple character-count checker might say "P@ssw0rd" (8 characters, mixed case, numbers, symbols) is strong. This tool detects that it is a common dictionary substitution and rates it far lower. Entropy alone is not enough — patterns, dictionary matches, and keyboard walks all reduce effective security. Our checker combines entropy calculation with pattern detection and breach-list awareness to give you a realistic assessment.

Security Weaknesses

Common Patterns That Lower Strength

Even passwords that look complex can contain predictable patterns attackers exploit. Here are the most common weaknesses our checker flags:

Dictionary Words

Words like "password," "sunshine," or "dragon" — even when capitalized or appended with symbols — are tested first by attackers. Letter-for-number substitutions (P@ssw0rd, H3llo) provide almost no protection because cracking tools already include every common l33t-speak variant.

Sequential Characters

"abc123," "zyx987," "abcdefg" — any predictable forward or backward sequence is trivially guessed. Attackers test every alphanumeric run before moving to random combinations.

Repeated Characters

"aaaaaa," "111111," "xxxx" — four or more identical consecutive characters dramatically shrink the search space. Repeating characters adds length but zero additional entropy.

Keyboard Patterns

"qwerty," "asdfgh," "zxcvbn," "1qaz2wsx" — passwords formed by walking across a keyboard are included in every default wordlist. They offer the illusion of randomness while being completely predictable.

Personal Information

Names, birthdates, phone numbers, addresses, or pet names. Targeted attacks scrape social media and public records to guess these first. Never use information that can be found about you online.

Common Password Roots

"password123," "letmein," "welcome1," "admin" — the top 100,000 passwords are tested in under a second on modern hardware. If your password is on any public top-100K list, it is crackable instantly regardless of other factors.

Best Practices

How to Use This Tool Effectively

1
Test your most-used passwords. Enter the passwords you actually rely on every day. If they rate "Weak" or "Dangerous," that is a signal to replace them immediately with generated passwords stored in a password manager.
2
High entropy is necessary but not sufficient. A password can have high entropy from length alone while still containing a dictionary word. Look for a "Strong" or "Very Strong" rating with no red diagnostics — that means both entropy and pattern checks passed.
3
Cross-check against breaches. A password can score "Perfect" structurally but still be unsafe if it has appeared in a data breach. After checking strength, use the Breach Checker to verify it has not been exposed in known leaks.
4
Do not rely solely on this tool. This checker evaluates structure and common patterns, but it cannot detect every weakness. Also watch for dictionary words, reuse across accounts, and whether your password is memorable enough to not be written down insecurely.

Introduction

You think your password is strong because it has a capital letter and a number. You're probably wrong. The Password Strength Checker goes beyond simple 'weak/medium/strong' labels to give you the actual math: entropy bits, estimated crack time under real-world attack scenarios, and whether your password matches patterns found in billions of leaked credentials. This is the difference between guessing your password is secure and knowing it.

What This Tool Does

A password strength checker is a tool that evaluates the security of a password by calculating its entropy (measured in bits), detecting common patterns (dictionary words, l33tsp34k substitutions, keyboard walks, repeating characters), and estimating crack time under real-world attack scenarios. Unlike simple meters that only check character classes, this tool applies Shannon information theory to measure actual unpredictability and compares the password against patterns found in billions of leaked credentials from breaches like RockYou2024. The output includes a numerical entropy score, pattern detection results, estimated crack time at different attack speeds, and actionable feedback on why the password is strong or weak.

Why It Matters

Most password strength meters lie to you. They award points for adding a '!' to the end of 'password' while ignoring that the underlying pattern is still trivially guessable. A 2023 study by researchers at the University of Cambridge found that the most popular password meters were wrong about 30% of the time, overestimating the strength of common patterns. Real security requires analyzing password entropy — the measurable unpredictability of a credential — not just checking boxes on a requirements list. The difference between a meter that says 'strong' and one that correctly identifies a crackable password is the difference between a false sense of security and actual protection.

How It Works

The checker first detects which character classes are present (lowercase, uppercase, digits, symbols) to determine the theoretical character pool size R. It calculates base entropy as L × log₂(R) where L is password length. It then applies pattern penalties: dictionary word detection subtracts 25 bits, l33tsp34k substitution detection subtracts 30 bits, keyboard walk detection subtracts 35 bits, repeating character detection subtracts 25 bits, and date pattern detection subtracts 30 bits. The effective entropy is the adjusted value after penalties. Crack time is calculated by dividing 2^entropy by the attack speed (100 guesses/second for online, 10 billion for offline GPU). The tool also checks the password against a database of breached credentials using k-anonymity — only a partial SHA-1 hash is transmitted, preserving privacy.

Educational Diagram

A flowchart showing the password analysis pipeline: Input Password → Character Class Detection → Pool Size Calculation → Base Entropy (L × log₂R) → Pattern Detection (dictionary, l33tsp34k, keyboard, repeating) → Entropy Penalties → Effective Entropy → Crack Time Estimation → Rating Output. Side panel shows pattern penalty values and attack speed assumptions.

Step-by-Step Examples

Example 1: Analyzing a common 'strong' password
1

Enter 'P@ssw0rd123' into the input field — a password many meters rate as 'strong'

2

The checker detects the l33tsp34k substitution pattern (a→@, o→0) which attackers automatically try

3

Pattern matching finds this is a dictionary word with predictable modifications

4

The entropy calculation shows only ~28 bits despite meeting typical complexity requirements

ResultPattern detected: dictionary word with l33tsp34k substitutions. Entropy: 28.4 bits. Crack time at 10B guesses/sec: under 5 minutes. Rating: Weak despite meeting complexity rules.
Example 2: Analyzing a truly random password
1

Enter 'k9$mPx2#nLq!vR7@' into the input field — a cryptographically generated 16-character password

2

The checker finds no dictionary words, no keyboard patterns, no personal information patterns

3

Full character pool detected: uppercase, lowercase, digits, and symbols

4

The entropy calculation shows 105.1 bits — computationally infeasible to brute-force

ResultNo patterns detected. Entropy: 105.1 bits. Crack time at 10B guesses/sec: 317 billion years. Rating: Very Strong.

Code Examples

javascriptPassword entropy calculation with pattern detection
function analyzePasswordStrength(password) {
  let poolSize = 0;
  const hasLower = /[a-z]/.test(password);
  const hasUpper = /[A-Z]/.test(password);
  const hasDigit = /[0-9]/.test(password);
  const hasSymbol = /[^a-zA-Z0-9]/.test(password);

  if (hasLower) poolSize += 26;
  if (hasUpper) poolSize += 26;
  if (hasDigit) poolSize += 10;
  if (hasSymbol) poolSize += 33;

  let entropy = password.length * Math.log2(poolSize || 1);

  const penalties = [];
  const l33tMap = { '@': 'a', '0': 'o', '1': 'l', '3': 'e', '4': 'a', '5': 's', '7': 't', '$': 's' };
  const deL33ted = password.split('').map(c => l33tMap[c] || c).join('').toLowerCase();

  const commonWords = ['password', 'qwerty', 'admin', 'letmein', 'welcome'];
  if (commonWords.some(w => deL33ted.includes(w))) {
    entropy -= 25;
    penalties.push('Contains common dictionary word');
  }

  if (/(.)\1{2,}/.test(password)) {
    entropy -= 15;
    penalties.push('Contains repeated characters');
  }

  const keyboardPatterns = ['qwerty', 'asdfgh', 'zxcvbn', '123456'];
  if (keyboardPatterns.some(p => deL33ted.includes(p))) {
    entropy -= 20;
    penalties.push('Contains keyboard pattern');
  }

  const combinations = Math.pow(2, Math.max(entropy, 0));
  const crackTimeSeconds = combinations / 1e10;

  return {
    entropy: Math.max(entropy, 0).toFixed(1),
    combinations: combinations.toExponential(2),
    crackTime: formatTime(crackTimeSeconds),
    rating: entropy > 100 ? 'Very Strong' : entropy > 80 ? 'Strong' : entropy > 60 ? 'Moderate' : entropy > 40 ? 'Weak' : 'Very Weak',
    penalties
  };
}

function formatTime(seconds) {
  if (seconds < 1) return 'instant';
  if (seconds < 60) return seconds.toFixed(0) + ' seconds';
  if (seconds < 3600) return (seconds / 60).toFixed(0) + ' minutes';
  if (seconds < 86400) return (seconds / 3600).toFixed(0) + ' hours';
  if (seconds < 31536000) return (seconds / 86400).toFixed(0) + ' days';
  return (seconds / 31536000).toExponential(1) + ' years';
}

console.log(analyzePasswordStrength('P@ssw0rd123'));
// { entropy: "28.4", rating: "Weak", penalties: ["Contains common dictionary word"] }
javascriptDetecting common password patterns
function detectPasswordPatterns(password) {
  const patterns = {
    dictionary: false, l33tsp34k: false, keyboard: false,
    repeating: false, sequential: false, date: false
  };

  const l33tMap = { '@':'a','0':'o','1':'l','3':'e','4':'a','5':'s','7':'t','$':'s' };
  const normalized = password.split('').map(c => l33tMap[c] || c).join('').toLowerCase();

  const top100 = ['password','123456','12345678','qwerty','abc123','monkey','master'];
  if (top100.includes(normalized)) patterns.dictionary = true;

  if (password !== normalized && normalized !== password.toLowerCase()) {
    patterns.l33tsp34k = true;
  }

  const kbRows = ['qwertyuiop','asdfghjkl','zxcvbnm','1234567890'];
  const lower = password.toLowerCase();
  for (const row of kbRows) {
    for (let len = 4; len <= row.length; len++) {
      for (let i = 0; i <= row.length - len; i++) {
        const seq = row.slice(i, i + len);
        if (lower.includes(seq)) patterns.keyboard = true;
      }
    }
  }

  if (/(.)\1{2,}/.test(password)) patterns.repeating = true;

  return patterns;
}

console.log(detectPasswordPatterns('P@ssw0rd123'));
// { dictionary: true, l33tsp34k: true, keyboard: false, repeating: false }

Entropy vs Real-World Security

Entropy (bits)CombinationsCrack Time (10B/s)Security LevelExample
282.7 × 10⁸< 1 secondTrivially crackableP@ssw0rd123
401.1 × 10¹²2 minutesVery WeakTr0ub4dor&3
601.1 × 10¹⁸3.6 yearsWeakcorrect horse battery staple
801.2 × 10²⁴3.8 million yearsStrongk9$mPx2#nLq!vR7@
1054.1 × 10³¹130 billion yearsVery StrongaK9$mPx2#nLq!vR7@wYz
1283.4 × 10³⁸1.1 × 10¹⁹ yearsMaximum256-bit key material

Common Patterns Attackers Try First

Pattern TypeExampleDetection MethodEntropy Reduction
Dictionary wordpasswordDictionary lookup (100K+ words)-40 bits
L33tsp34kp@ssw0rdCharacter substitution mapping-30 bits
Keyboard walkqwertyKeyboard adjacency analysis-35 bits
Repeating charsaaa111Repetition detection-25 bits
Date pattern19900101Date format recognition-30 bits
Personal infojohn1985Name + year correlation-20 bits

Benefits

  • Analyzes password entropy using Shannon information theory for mathematically accurate strength measurement.
  • Detects l33tsp34k substitutions, dictionary words, keyboard walks, and other common patterns attackers exploit first.
  • Provides real-world crack time estimates based on current GPU hardware capabilities (10B+ guesses/second).
  • Flags passwords found in known breach databases — checking against billions of leaked credentials.
  • Offers specific, actionable feedback on why a password is weak rather than just a vague rating.

Use Cases

01

Evaluating whether an existing password you've been using for years is actually secure enough to protect your accounts.

02

Testing passwords before deployment to verify they meet your organization's actual security requirements.

03

Educating users on why their 'clever' password modifications (adding '123' or '!' to the end) don't meaningfully improve security.

04

Auditing exported password vaults to identify weak credentials that need immediate replacement.

Common Mistakes to Avoid

✗

Trusting simple 'weak/medium/strong' meters that only check length and character classes without detecting common patterns.

✗

Assuming l33tsp34k substitutions (a→@, o→0) add meaningful security — attackers have been trying these substitutions for 20+ years.

✗

Believing that adding a number to the end of a dictionary word ('password1') makes it strong — this is one of the first patterns attackers try.

✗

Ignoring that passwords found in breach databases are checked first regardless of their theoretical entropy — if it's been leaked, it's compromised.

Security Implications

A password that looks strong to a human can be trivially cracked by an attacker. The 2023 Verizon DBIR found that 49% of breaches involved stolen credentials, and automated tools now test billions of leaked password patterns per day. Password strength meters that don't detect real-world patterns give users a false sense of security. A password like 'P@ssw0rd123' meets every complexity requirement but is cracked in under 5 minutes because it's a known pattern. Real security requires entropy-based analysis that accounts for the attacks criminals actually use.

Security Information

All analysis runs client-side in your browser. Password data is never transmitted to external servers. When checking against breach databases, only a partial SHA-1 hash (first 5 characters) is sent using k-anonymity — your full password never leaves your device. The entropy calculations are based on Shannon's information theory and are mathematically provable. Pattern detection uses the same techniques as commercial password crackers (Hashcat rules, John the Ripper wordlists) to identify weaknesses before attackers do.

Best Practices

  • Aim for 80+ bits of entropy for general accounts, 100+ bits for high-value accounts like email and banking.
  • Don't trust simple 'weak/medium/strong' meters — verify that the tool detects patterns, not just character classes.
  • Check your existing passwords against breach databases immediately — if they appear, replace them.
  • Use cryptographically generated passwords (16+ characters) stored in a password manager instead of creating passwords yourself.
  • Ignore advice to add special characters at predictable positions — random placement is stronger.

Frequently Asked Questions

Fundamentals

What is Password Strength?

Password strength is a measure of how resistant a password is to guessing and brute-force attacks. Unlike simple metrics like length or character types, strength combines multiple factors including entropy, dictionary presence, pattern analysis, and common password databases. Our strength checker provides a comprehensive rating from "Very Weak" to "Very Strong" based on these combined factors.

Understanding password strength is crucial for protecting your accounts. A strong password can withstand billions of guessing attempts, while a weak one can be cracked in seconds. Our tool analyzes your password against known attack patterns and provides actionable feedback for improvement.

Technical Deep Dive

How Password Strength Analysis Works

Our strength checker performs multiple analyses simultaneously. Entropy calculation measures the password's information content based on length and character diversity. Dictionary checking compares the password against lists of common passwords, dictionary words, and known compromised credentials.

Pattern detection identifies keyboard walks (qwerty), sequential characters (abc, 123), repeated characters (aaa), and common substitutions (p@ssw0rd). These patterns reduce effective entropy even when the password appears complex.

Crack time estimation translates the analysis results into practical timeframes, showing how long the password would resist different attack scenarios. The final strength rating combines all these factors into a single, easy-to-understand assessment.

Practical Applications

Why Password Strength Matters

Account Security: Your password is the primary barrier protecting your accounts. A strong password prevents unauthorized access even if an attacker obtains your username. Password strength directly determines how long your accounts remain secure.

Breach Protection: When data breaches occur, attackers attempt to crack leaked password hashes. Strong passwords resist cracking attempts, protecting your accounts even after a breach. Weak passwords can be cracked in seconds, exposing all accounts using the same credentials.

Password Policy Compliance: Many organizations require minimum strength levels for user passwords. Our strength checker helps users create passwords that meet these requirements before attempting to set them.

Security Awareness: Understanding what makes a password strong helps users make better security decisions. The detailed feedback explains why a password is weak and how to improve it, building long-term security habits.

Security Pitfalls

Password Strength Mistakes

Ignoring Dictionary Warnings: If the strength checker identifies a dictionary word, do not ignore it. Attackers use dictionary attacks that test millions of common words and phrases. Replace dictionary words with random characters or use a passphrase generator.

Over-relying on Complexity: Adding a single symbol or number at the end (like "password!") provides minimal security improvement. Focus on length and randomness instead. A 16-character lowercase password is stronger than an 8-character complex one.

Reusing Strong Passwords: Even the strongest password becomes a liability if reused across multiple sites. A breach on one site exposes all accounts using that password. Use unique passwords for each account.

Not Re-checking After Changes: When modifying a password based on feedback, re-check it to ensure the changes improved rather than weakened the password. Sometimes adding characters can inadvertently create new patterns.

Related Tools

Related Password Security Tools

Explore these complementary password security tools:

Try It Yourself

Pattern Detective

Type a password below and see exactly which patterns the strength checker detects. Each weakness is highlighted so you understand why your password is strong or weak.

Type a password above to see pattern analysis...

Entropy 0 bits
Pool Size 0 characters

Frequently Asked Questions

What makes a password strong?
Length is the most important factor. A 16-character lowercase password is stronger than an 8-character complex one. True randomness matters more than character variety — use a generator rather than inventing patterns.
Is a strong password enough?
No. Strong passwords should be combined with unique passwords per account, two-factor authentication, and a password manager. Security is layered — no single measure is sufficient.
Should I use a password manager?
Yes. Password managers let you use unique, high-entropy passwords for every account without memorization burden. Generate random 16+ character passwords and store them in your manager. Only memorize your master password.
How often should I check my passwords?
Check when creating or changing a password. Also re-check after hearing about data breaches. If any password rates "Weak" or "Dangerous," change it immediately on all affected accounts.
Does this tool store my password?
No. All analysis happens in your browser. The password is never sent to any server. This tool works offline — no data leaves your device.
Honest Limitations

What This Tool Cannot Tell You

It cannot check if your password is in a breach database

This tool analyzes structural strength only. Use our Breach Checker to verify against known data breaches.

Heuristic ratings are imperfect

The strength meter uses pattern matching and entropy estimation. It cannot detect every weak pattern, and some structurally strong passwords may still be vulnerable to targeted attacks.

Crack time estimates are theoretical

Real-world crack times depend on the hash algorithm used by the service, attacker hardware, and attack strategy. These estimates assume a brute-force approach against a fast hash.

It does not check reuse

A password can score "Perfect" here but still be unsafe if you use it on multiple accounts. Always use unique passwords per service.