Password Strength Checker
How long would your password survive an attack? Find out without it leaving your device.
Password
Analysed on this device as you type — never sent or stored.
Personal details (optional)
Your name, username, email, birthday, pet, city or the site’s name, separated by commas. Used only to test this password; never stored.
Strength
—
Type a password to see how strong it is.
| Attack | Time to guess |
|---|---|
| Online, rate-limited A website that limits failed sign-ins. 100 guesses per hour. | — |
| Online, no rate limit A service without limits on failed sign-ins. 10 guesses per second. | — |
| Stolen database, slow hash Salted bcrypt, scrypt, Argon2 or PBKDF2, several attackers. 10⁴ guesses per second. | — |
| Stolen database, fast hash Salted MD5, SHA-1 or SHA-256 on GPUs. 10¹⁰ guesses per second. | — |
NIST SP 800-63B-4 checklist
- Type a password to run the checks.
Check breaches looks the password up in Have I Been Pwned: only the first 5 characters of its SHA-1 hash are sent, and the match is found on this device.
How an attacker would read it
| Part | What it is | Guesses |
|---|---|---|
| — | ||
The parts are masked while the password is hidden. Press Show to see them.
About the Password Strength Checker
Most strength meters count character types, but attackers do not guess that way: they try common passwords, dictionary words, names, keyboard patterns, dates and predictable substitutions first. This checker uses zxcvbn-ts, the open-source TypeScript edition of Dropbox's zxcvbn estimator (Wheeler, USENIX Security 2016), with 49,233 common passwords, about 187,000 English words and names and six keyboard layouts. It estimates how many guesses a smart attacker would need, how long that takes in four attack scenarios, and which part of the password gives it away.
A checklist applies the password rules of NIST's Digital Identity Guidelines (SP 800-63B-4): length, blocklists of common and dictionary passwords, personal details and Unicode handling. Check breaches looks the password up in Have I Been Pwned without sending it. Everything else happens on your device; nothing you type is stored.
How to use it
- Type or paste a password. It is analysed as you type, on your device.
- Optionally add Personal details — your name, username, email or the site's name — which are the first things a targeted attacker tries.
- Read the score, the estimated number of guesses, the crack times and the feedback on what makes it weak.
- Go through the NIST checklist, and press Check breaches to look the password up in Have I Been Pwned (only 5 characters of its SHA-1 hash are sent).
- Press Show password to see which part matched which pattern.
Examples
P@ssw0rd
Very weak (0 of 4) — "password" with look-alike substitutions, about 17 guesses
Attackers try such substitutions right after the original word.
Tr0ub4dor&3
Weak (1 of 4) — close to the word "troubadours", about 7.6 × 10⁵ guesses
Found by the look-alike search: a misspelt word with substitutions is still a word. About 1 minute against a stolen bcrypt database.
correcthorsebatterystaple
Very strong (4 of 4) — four dictionary words, about 6.3 × 10¹² guesses
About 20 years against a slow hash but only about 10 minutes against a fast one — and as a famous example it is on attackers' lists anyway. Use more words, chosen at random.
Common uses
- Checking a password you made up before using it for an important account.
- Seeing why a password a site rejected is weak, and what to change.
- Explaining password strength to family, students or colleagues with real examples.
- Checking passwords against NIST SP 800-63B-4 rules while designing a sign-up form.
How the estimate works
zxcvbn splits the password into the cheapest-to-guess sequence of patterns — dictionary words (including reversed words and l33t substitutions such as @ for a), look-alike misspellings of listed words, keyboard patterns on QWERTY, QWERTZ, AZERTY, Dvorak and number pads, repeats, sequences, dates and recent years — and multiplies the guesses each part needs. Characters that match no pattern count 10 guesses each. The score follows zxcvbn's thresholds: under 10³ guesses scores 0, under 10⁶ scores 1, under 10⁸ scores 2, under 10¹⁰ scores 3, and 10¹⁰ or more scores 4.
That models how real cracking tools work, which is why "P@ssw0rd!" scores far lower than a meter that counts symbols would suggest. The look-alike search is slower, so it runs a moment after you stop typing.
The four attack scenarios
The crack times use zxcvbn's standard assumptions:
- Online, rate-limited — 100 guesses per hour against a website that limits failed sign-ins.
- Online, no rate limit — 10 guesses per second.
- Stolen database, slow hash — 10⁴ guesses per second against salted bcrypt, scrypt, Argon2 or PBKDF2 hashes, with several attackers.
- Stolen database, fast hash — 10¹⁰ guesses per second against salted MD5, SHA-1 or SHA-256 on graphics cards.
You cannot know how a site stores your password, so judge important passwords by the fast-hash scenario — and never reuse a password, because one breached site is enough.
NIST SP 800-63B-4 password rules
The NIST Digital Identity Guidelines (section 3.1.1.2) tell services — some points as requirements, others as recommendations — to:
- require at least 15 characters for passwords used on their own, and at least 8 for passwords used only with multi-factor authentication;
- accept at least 64 characters, all printable ASCII characters, spaces and Unicode, counting each Unicode code point as one character (and normalise it with NFC);
- impose no composition rules — no "must contain a digit and a symbol" — and no periodic password changes, but force a change when there is evidence of compromise;
- compare every new password, as a whole, against a blocklist of commonly used, expected or compromised passwords: breach corpuses, dictionary words and context-specific words such as the service name or username;
- allow password managers, autofill and paste, and limit failed sign-in attempts.
The checklist on this page applies the rules that can be checked from the password alone.
About the word lists
zxcvbn-ts is MIT-licensed (© Dan Wheeler, Dropbox and the zxcvbn-ts contributors). Its English common-word list is derived from the OpenSubtitles 2024 corpus provided by OPUS (Helsinki-NLP), used under the Open Data Commons Attribution Licence (ODC-BY); the other lists cover common passwords, first names, surnames, words frequent on English Wikipedia and the EFF Diceware words. They are about 0.9 MB compressed, downloaded from MySmartCoPilot the first time you type and then kept by your browser.
Limitations
- It is an estimate, not a guarantee. An attacker who knows you personally can do better; a password made by a generator is stronger than estimated, because unexplained characters only count 10 guesses each.
- The dictionaries are English, so words from other languages are treated as random characters and may be rated too highly.
- Only the first 256 characters are analysed.
- If the look-alike search takes too long for a password (mostly ones full of digits and symbols), the result without it is shown and marked.
Privacy
The strength check runs in your browser: what you type is never uploaded, stored or logged. The first time you type, zxcvbn's word lists (about 0.9 MB) are downloaded from MySmartCoPilot. Only if you press Check breaches are the first 5 characters of the password's SHA-1 hash — never the password — sent to Have I Been Pwned's Pwned Passwords API.
Frequently asked questions
Is it safe to type my real password here?
The password is analysed by your browser and is never sent or stored; the page works offline once the word lists have loaded. The breach check is optional and sends only 5 characters of the password's SHA-1 hash. As a habit, though, avoid typing important passwords into sites you have no reason to trust.
My password has symbols and numbers. Why is it weak?
Because the symbols are predictable: capital first letter, a word, a year or "123" at the end, @ for a and 0 for o. Cracking tools try exactly these patterns early. Length and randomness matter far more than character types.
What score should I aim for?
4 (very strong) for email, banking, work and password-manager master passwords; at least 3 for everything else. Easiest: let a password manager generate a long random password for each site, or use a random passphrase of six or more words.
Why are the crack times so different?
They depend on where the attacker guesses. A website with rate limits allows only a few tries an hour; a stolen database lets attackers guess offline as fast as their hardware allows — billions of times per second if the site used a fast hash.
Does it check whether my password was leaked?
Only when you press Check breaches. It then uses Have I Been Pwned's k-anonymity API: only 5 characters of the password's SHA-1 hash are sent, and the match is found on your device. The Pwned Password Checker explains the method in detail.
How is this different from an entropy calculator?
Entropy calculators assume every character was chosen at random, so "Password1!" looks strong. zxcvbn models what attackers actually try, which gives far more realistic results for passwords people make up. For generated random passwords, the entropy shown by a password generator is the better measure.