Password Strength Checker

Type a password to see its strength rating and an estimate of how long it would take to crack, based on character variety, length, and easily guessed patterns. We recommend testing a similar password built the same way rather than the one you actually use.

All checks run inside your browser. Nothing you type is ever sent to or stored on our servers.

Password strength checker

What you type is discarded when you leave the page.

What this tool does

A password's strength comes down to how well it resists a brute-force attack, where an attacker tries every possible combination. The more character types and the longer the password, the more combinations there are, and the longer cracking takes.

However, even a long password is much easier to crack if it contains guessable patterns - common words, keyboard runs, or what looks like a birthday - because attackers try those first. This tool factors in such patterns along with character variety and length.

How to build a strong password

  • Prioritize length. Adding 4 more characters often helps more than adding a symbol.
  • A passphrase of several unrelated words is easy to remember and can be very strong.
  • Use a different password for every service. Reuse lets one breach spread to all your accounts.
  • A password manager lets you use long random passwords you could never memorize.
  • Where available, enable two-factor authentication (2FA) or passkeys as well.

Frequently asked questions

Is it safe to type my real password here?

The check runs entirely inside your browser, and nothing is sent or stored. If you would still rather not, test a similar password built the same way (same length, character types, and structure) - the rating will be the same.

If it says "strong", am I completely safe?

No. This tool only estimates resistance to brute-force attacks. A password stolen through phishing or leaked from a service cannot be protected by strength alone. Avoid reuse and enable two-factor authentication.

How is the time to crack estimated?

It is approximated from the character types used, the length, and whether guessable patterns are present, assuming a typical attack setup. Actual times vary widely with the attacker's hardware and methods, so treat it as a comparative guide.

Should I change my passwords regularly?

Current guidance is that strong passwords do not need scheduled changes unless there are signs of a breach. Forced rotation tends to produce weaker passwords and reuse. Do change immediately if you suspect a leak.

Related terms and articles