Checking…
Password strength checker
Understand common patterns and estimated guessability. Analyze a candidate locally, with no password upload.
Checking…
Understand common patterns and estimated guessability. Analyze a candidate locally, with no password upload.
Checking…
Checking…
Local analysis. The password stays in this tab and is never sent for checking. Prefer a new candidate, not a password you already use.
Ready for a local check.
This password strength checker estimates how predictable a candidate looks to a dictionary and pattern model. Enter a new candidate, choose Check strength, and read the explanation below the form. The password strength checker does not ask for an account name or sign-in address. You can explore different approaches without identifying the account you intend to protect.
The password strength checker accepts one to 128 Unicode characters, including spaces. It preserves your input exactly instead of removing leading spaces, changing capitalization or silently shortening a long value. An invalid length produces a message without a score. A displayed character count refers to Unicode code points, which may differ from the number of visible symbols.
The password strength checker starts only after an explicit click. Its first run downloads the analysis model from this site's static assets; the candidate is then processed in a dedicated browser worker. The model is not loaded for an ordinary visit to the homepage. Subsequent visits may reuse cached code, although no previously entered candidate is restored.
Use Show password only when your surroundings allow it. The password strength checker initially masks input and masks it again when analysis starts. Masking reduces casual screen exposure; it is not encryption or protection against software that can read the browser. Prefer testing a new candidate or a disposable example rather than pasting a credential you already use.
Editing input removes the previous password strength checker result and cancels any current calculation. This prevents an old score from appearing to describe your new text. Changes are not checked automatically, so you can finish editing before choosing Check again. A result remains associated with the candidate that produced it until you edit or clear the form.
Stop and clear terminates the current password strength checker worker and empties the input. Clear also removes a completed result. Hiding the tab, leaving the page or navigating to another tool discards the working data. If you switch applications while composing a candidate, expect to enter it again; this tool is not a draft editor or vault.
The password strength checker allows fifteen seconds for loading and computation together. A slow connection, a blocked asset or an unusually expensive input can prevent a result. The page reports that failure rather than substituting a positive score. Retry deliberately when ready, or use the generator to create a fresh candidate without waiting for analysis.
The password strength checker shows a model score from zero to four. Zero means the model finds the candidate very easy to guess; four is its highest band. The bar is not a percentage, a probability of compromise or an account certification. Moving between bands is useful feedback, but small edits that raise a score do not establish uniqueness.
The password strength checker uses the default scoring from zxcvbn-ts, with its common and English dictionaries and supplied keyboard graphs. The model considers familiar text and structured patterns. Its result is an estimate under that configuration, not a measurement of an attacker trying your candidate against a real account.
The password strength checker also displays an approximate guess count as a power of ten. For example, ten to the sixth power represents about one million guesses in the model. We round the displayed exponent to one decimal place. This compact notation avoids long strings of digits that suggest more precision than a guessability model can support.
The password strength checker does not convert that count into seconds, years or centuries. A real attack depends on the service, storage scheme, rate limits, attacker knowledge and available computing resources. We do not observe those conditions. A large estimate therefore cannot justify a statement that a particular account will remain uncompromised for a certain duration.
A dictionary category in the password strength checker means that part of the model's chosen explanation matches familiar text. Names, words and predictable substitutions can appear in this category. The tool shows only the category and general advice. It does not print the matched substring next to a masked input, where that would unexpectedly expose part of your candidate.
Repeated segments and ordered sequences receive separate password strength checker explanations. A long-looking string made by repeating a short unit can still be predictable. Likewise, a run of consecutive letters or digits can be described compactly by an attacker. Consider changing the selection method rather than merely adding another copy of the same unit or extending the same sequence.
Keyboard walks and dates can also appear in the password strength checker. These categories describe recognizable structure, not a claim that the tool knows which keyboard you own or whose birthday a number represents. The model configuration is documented in the estimator options. It does not query your contacts, keyboard history or personal records.
Other segments in the password strength checker means the selected explanation includes text without a cheaper named pattern. It does not mean those characters were randomly generated. A quotation unknown to this dictionary, a non-English phrase or a personally meaningful string can receive an optimistic estimate. Model coverage is an important reason to avoid treating the highest band as proof.
Copy summary exports the password strength checker method versions, score, rounded estimate, length, category names and scope statement. It excludes the candidate and matched fragments. You can compare model results without copying the secret itself. Length and categories can still be informative, so share the summary intentionally and avoid attaching it to identifying account details unnecessarily.
The password strength checker does not erase your system clipboard after copying. Clipboard managers, device synchronization and other applications can retain copied summaries according to their own settings. Clearing the form removes this page's working result only. Before sharing a screenshot, also check that the input is masked and that unrelated browser or account information is not visible.
The password strength checker sends no password, digest or hash prefix to an analysis endpoint. There is no remote breach matcher in this workflow. Normal page delivery still requires network requests, and site analytics remain separate from the local calculation. Our implementation does not attach the candidate or result to analytics events, URLs or browser storage.
The password strength checker is not a security boundary against a compromised device, malicious extension or untrusted page script. Browser processing reduces the data intentionally sent for this feature; it cannot control every program installed on your device. Use a trusted browser environment and read the privacy policy for the site's broader data flows before handling sensitive information.
The password strength checker clears its active state and terminates its worker when you leave, hide the tab or clear the form. That behavior limits accidental retention in the interface. It does not promise forensic erasure of browser memory, operating-system swap, screen recordings or browser-managed input history. The site offers no recovery mechanism for a discarded candidate.
The password strength checker does not establish whether a value has appeared in a breach. Its common-password dictionary is a model input, not a complete or current incident database. A low score can help identify a predictable choice. A high score cannot prove that a unique-looking value has never been leaked, phished, shared or captured elsewhere.
The password strength checker cannot determine reuse across accounts. Entering the same candidate twice produces no cross-site investigation and no account inventory. Treat uniqueness as a separate requirement. If you know a password is reused or compromised, changing its spelling until the bar improves is not a substitute for replacing the affected credentials through their genuine account settings.
The password strength checker has limited coverage beyond its configured English and common dictionaries. Unicode input is supported, but a model can miss familiar expressions in another language. We display an extra coverage notice for non-ASCII or control characters. Services may normalize text or count characters differently, so confirm the destination accepts exactly the credential you intend to save.
The password strength checker is most useful as feedback on a selection process. For a fresh random string, use the password generator and save the chosen value with an appropriate password manager. Generating a candidate, evaluating it and registering it with a service are separate operations. None of these local tools changes an account on your behalf.
A password strength checker score is not a replacement for current authentication guidance. NIST SP 800-63B-4 specifies fifteen characters for single-factor passwords, permits shorter minima in multi-factor contexts, and rejects arbitrary composition rules. Those are verifier requirements in their stated scope; this page's input range is an analysis limit, not a universal password policy.
Use the password strength checker alongside the destination's actual protections and recovery options. Where available, consider phishing-resistant sign-in and keep recovery access secure. The estimator does not inspect those settings or verify enrollment. A unique long credential can still be stolen through an unrelated mechanism, so focus on account access and recovery rather than collecting a particular bar color.
Can I test an existing password? The password strength checker can process any supported text, but a new candidate or disposable example is the better choice for exploration. There is no need to provide a real username or current credential. If you suspect compromise, use the account's genuine recovery and password-change process instead of relying on this score.
Why did adding a symbol barely help? The password strength checker looks for recognizable structure rather than simply counting character classes. A predictable substitution or suffix can leave the underlying choice easy to describe. Try a different selection method and a fresh independent candidate. Do not adopt publicly displayed examples from this article or any other tutorial as secrets.
Why is my long phrase rated lower than expected? A password strength checker can recognize repeated words, familiar sequences or dictionary combinations even when the text occupies many characters. The displayed categories explain its selected model. Conversely, an unfamiliar phrase can be overestimated. Length, generation method, uniqueness and model coverage should be considered together when interpreting the result.
Does four out of four mean safe? No. The password strength checker has a highest model band, not a universal safety state. It has not observed the target account, tested all guessing strategies or checked exposure. Keep the distinction visible when sharing a report: an estimate can support a choice without proving that the complete account is secure.
Can this work without JavaScript or workers? The password strength checker requires both for local computation. Its article remains readable before the interactive controls are ready, and the controls stay disabled until event handlers are attached. If worker loading fails, analysis returns an unavailable message. There is no server submission fallback that silently changes where the candidate is processed.
Is this an entropy calculator? The password strength checker reports estimated guesses from a pattern model. It does not infer the probability distribution that produced your candidate or label a character-count formula as measured entropy. The distinction matters for human choices, which can look varied while following familiar construction rules. Read the model result as a diagnostic explanation.
Where can I verify the method? The password strength checker identifies the pinned estimator and dictionary versions in every result. Its source model is described by the linked project documentation; the broader approach was evaluated in the original zxcvbn research. The password strength checker interface, data handling and execution limits are separate implementation choices explained above.
Software and dictionary attribution is available in the model license notices.