Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Password Strength Checker

How long would your password survive an attack? Find out without it leaving your device.

Security No upload Works offline Uses live data Free, no sign-up

Password

Analysed on this device as you type — never sent or stored.

Personal details (optional)

Your name, username, email, birthday, pet, city or the site’s name, separated by commas. Used only to test this password; never stored.

Strength

—

Type a password to see how strong it is.

—Estimated guesses
—As bits of entropy
—Characters
Time to guess the password
AttackTime to guess
Online, rate-limited A website that limits failed sign-ins. 100 guesses per hour. —
Online, no rate limit A service without limits on failed sign-ins. 10 guesses per second. —
Stolen database, slow hash Salted bcrypt, scrypt, Argon2 or PBKDF2, several attackers. 10⁴ guesses per second. —
Stolen database, fast hash Salted MD5, SHA-1 or SHA-256 on GPUs. 10¹⁰ guesses per second. —

NIST SP 800-63B-4 checklist

  • Type a password to run the checks.

Check breaches looks the password up in Have I Been Pwned: only the first 5 characters of its SHA-1 hash are sent, and the match is found on this device.

How an attacker would read it

Patterns found in the password
PartWhat it isGuesses
—

The parts are masked while the password is hidden. Press Show to see them.

Next steps

About the Password Strength Checker

Most strength meters count character types, but attackers do not guess that way: they try common passwords, dictionary words, names, keyboard patterns, dates and predictable substitutions first. This checker uses zxcvbn-ts, the open-source TypeScript edition of Dropbox's zxcvbn estimator (Wheeler, USENIX Security 2016), with 49,233 common passwords, about 187,000 English words and names and six keyboard layouts. It estimates how many guesses a smart attacker would need, how long that takes in four attack scenarios, and which part of the password gives it away.

A checklist applies the password rules of NIST's Digital Identity Guidelines (SP 800-63B-4): length, blocklists of common and dictionary passwords, personal details and Unicode handling. Check breaches looks the password up in Have I Been Pwned without sending it. Everything else happens on your device; nothing you type is stored.

How to use it

  1. Type or paste a password. It is analysed as you type, on your device.
  2. Optionally add Personal details — your name, username, email or the site's name — which are the first things a targeted attacker tries.
  3. Read the score, the estimated number of guesses, the crack times and the feedback on what makes it weak.
  4. Go through the NIST checklist, and press Check breaches to look the password up in Have I Been Pwned (only 5 characters of its SHA-1 hash are sent).
  5. Press Show password to see which part matched which pattern.

Examples

Symbols do not help a common password
Input
P@ssw0rd
Result
Very weak (0 of 4) — "password" with look-alike substitutions, about 17 guesses

Attackers try such substitutions right after the original word.

The xkcd 936 example
Input
Tr0ub4dor&3
Result
Weak (1 of 4) — close to the word "troubadours", about 7.6 × 10⁵ guesses

Found by the look-alike search: a misspelt word with substitutions is still a word. About 1 minute against a stolen bcrypt database.

Random words
Input
correcthorsebatterystaple
Result
Very strong (4 of 4) — four dictionary words, about 6.3 × 10¹² guesses

About 20 years against a slow hash but only about 10 minutes against a fast one — and as a famous example it is on attackers' lists anyway. Use more words, chosen at random.

Common uses

  • Checking a password you made up before using it for an important account.
  • Seeing why a password a site rejected is weak, and what to change.
  • Explaining password strength to family, students or colleagues with real examples.
  • Checking passwords against NIST SP 800-63B-4 rules while designing a sign-up form.

How the estimate works

zxcvbn splits the password into the cheapest-to-guess sequence of patterns — dictionary words (including reversed words and l33t substitutions such as @ for a), look-alike misspellings of listed words, keyboard patterns on QWERTY, QWERTZ, AZERTY, Dvorak and number pads, repeats, sequences, dates and recent years — and multiplies the guesses each part needs. Characters that match no pattern count 10 guesses each. The score follows zxcvbn's thresholds: under 10³ guesses scores 0, under 10⁶ scores 1, under 10⁸ scores 2, under 10¹⁰ scores 3, and 10¹⁰ or more scores 4.

That models how real cracking tools work, which is why "P@ssw0rd!" scores far lower than a meter that counts symbols would suggest. The look-alike search is slower, so it runs a moment after you stop typing.

The four attack scenarios

The crack times use zxcvbn's standard assumptions:

  • Online, rate-limited — 100 guesses per hour against a website that limits failed sign-ins.
  • Online, no rate limit — 10 guesses per second.
  • Stolen database, slow hash — 10⁴ guesses per second against salted bcrypt, scrypt, Argon2 or PBKDF2 hashes, with several attackers.
  • Stolen database, fast hash — 10¹⁰ guesses per second against salted MD5, SHA-1 or SHA-256 on graphics cards.

You cannot know how a site stores your password, so judge important passwords by the fast-hash scenario — and never reuse a password, because one breached site is enough.

NIST SP 800-63B-4 password rules

The NIST Digital Identity Guidelines (section 3.1.1.2) tell services — some points as requirements, others as recommendations — to:

  • require at least 15 characters for passwords used on their own, and at least 8 for passwords used only with multi-factor authentication;
  • accept at least 64 characters, all printable ASCII characters, spaces and Unicode, counting each Unicode code point as one character (and normalise it with NFC);
  • impose no composition rules — no "must contain a digit and a symbol" — and no periodic password changes, but force a change when there is evidence of compromise;
  • compare every new password, as a whole, against a blocklist of commonly used, expected or compromised passwords: breach corpuses, dictionary words and context-specific words such as the service name or username;
  • allow password managers, autofill and paste, and limit failed sign-in attempts.

The checklist on this page applies the rules that can be checked from the password alone.

About the word lists

zxcvbn-ts is MIT-licensed (© Dan Wheeler, Dropbox and the zxcvbn-ts contributors). Its English common-word list is derived from the OpenSubtitles 2024 corpus provided by OPUS (Helsinki-NLP), used under the Open Data Commons Attribution Licence (ODC-BY); the other lists cover common passwords, first names, surnames, words frequent on English Wikipedia and the EFF Diceware words. They are about 0.9 MB compressed, downloaded from MySmartCoPilot the first time you type and then kept by your browser.

Limitations

  • It is an estimate, not a guarantee. An attacker who knows you personally can do better; a password made by a generator is stronger than estimated, because unexplained characters only count 10 guesses each.
  • The dictionaries are English, so words from other languages are treated as random characters and may be rated too highly.
  • Only the first 256 characters are analysed.
  • If the look-alike search takes too long for a password (mostly ones full of digits and symbols), the result without it is shown and marked.

Privacy

The strength check runs in your browser: what you type is never uploaded, stored or logged. The first time you type, zxcvbn's word lists (about 0.9 MB) are downloaded from MySmartCoPilot. Only if you press Check breaches are the first 5 characters of the password's SHA-1 hash — never the password — sent to Have I Been Pwned's Pwned Passwords API.

Frequently asked questions

Is it safe to type my real password here?

The password is analysed by your browser and is never sent or stored; the page works offline once the word lists have loaded. The breach check is optional and sends only 5 characters of the password's SHA-1 hash. As a habit, though, avoid typing important passwords into sites you have no reason to trust.

My password has symbols and numbers. Why is it weak?

Because the symbols are predictable: capital first letter, a word, a year or "123" at the end, @ for a and 0 for o. Cracking tools try exactly these patterns early. Length and randomness matter far more than character types.

What score should I aim for?

4 (very strong) for email, banking, work and password-manager master passwords; at least 3 for everything else. Easiest: let a password manager generate a long random password for each site, or use a random passphrase of six or more words.

Why are the crack times so different?

They depend on where the attacker guesses. A website with rate limits allows only a few tries an hour; a stolen database lets attackers guess offline as fast as their hardware allows — billions of times per second if the site used a fast hash.

Does it check whether my password was leaked?

Only when you press Check breaches. It then uses Have I Been Pwned's k-anonymity API: only 5 characters of the password's SHA-1 hash are sent, and the match is found on your device. The Pwned Password Checker explains the method in detail.

How is this different from an entropy calculator?

Entropy calculators assume every character was chosen at random, so "Password1!" looks strong. zxcvbn models what attackers actually try, which gives far more realistic results for passwords people make up. For generated random passwords, the entropy shown by a password generator is the better measure.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.