Password strength checker
Type a password to see its strength, character mix, and entropy — privately.
How the password strength checker works
Type any password and the meter updates live. Strength is estimated from entropy — length multiplied by the size of the character pool you actually used (lowercase, uppercase, digits, symbols). Each extra bit of entropy doubles the guessing effort, which is why a long simple password usually beats a short complex one.
As a rule of thumb: under 36 bits is weak, 36–59 bits is fair, 60–79 is strong, and 80+ is very strong. The breakdown shows exactly which character types you’re using, so you can see what’s missing.
This is an estimate, not a guarantee — common words and predictable patterns (“Password123!”) are weaker than their entropy suggests. Never reuse one password across accounts.
Password strength checker FAQ
Is my password sent anywhere?
No — everything runs in your browser. The password you type is never uploaded, stored, logged, or transmitted in any form.
What is entropy?
A measure of unpredictability in bits. It is calculated as password length × log₂ of the character-pool size. Each additional bit doubles the number of guesses an attacker would need in a brute-force attempt.
What counts as a strong password?
Aim for 60+ bits of entropy as a solid baseline and 80+ for important accounts. In practice that means long and unique — length contributes more than exotic symbols.
Should I test my real passwords here?
Technically it is safe, since nothing leaves the page. As a habit, though, test passwords that are similar — not identical — to the ones you actually use.