Password Strength Checker
Type a password to see its security score (0–100) and time to crack. For example, Summer2024! has upper and lower case, a number and a symbol, yet it is a common pattern: 38 (Shaky) and less than a second on a fast rig. Everything is calculated on your device.
Group security scoreboard
Compare security scores with friends, coworkers or family. “Find the weak link” unlocks at 3 people.
The scoreboard only stores your name, security score and leaked yes/no. Never your password, its hash or the breach count.
Score bands and grades
| Grade | Score | Meaning |
|---|---|---|
| 90–100 | Centuries even for fast cracking rigs | |
| 70–89 | Hard to crack with realistic attacks | |
| 45–69 | Survives slow hashes, at risk with fast ones | |
| 20–44 | Falls quickly to dictionary and pattern attacks | |
| 0–19 | On attackers’ first-try lists | |
| ≤ 10 | Found in breaches — change it now, whatever its length |
Score = estimated guesses as a power of ten × 5; 1020 guesses or more is 100. Time to crack assumes a fast offline attack at 10 billion guesses per second.
How attackers crack weak passwords
- Brute force: trying every combination of characters. Short passwords fall fast.
- Dictionary attacks: common words, names, dates and keyboard patterns (qwerty, 1q2w3e4r) go first.
- Credential stuffing: replaying email and password pairs leaked from other sites — which is why a breach check matters more than length.
- Phishing: fake login pages that make you type it in. Two-factor authentication is the last line of defense.
What makes a strong password
- Length: 12+ characters, ideally 16+. Every extra character multiplies the work.
- Unpredictable: no dictionary words, names, birthdays or obvious swaps like “P@ssw0rd”.
- Unique: a different password for every site, so one breach doesn’t cascade.
- Memorable: four unrelated words strung together are long and still easy to remember.
How to use the password strength checker
- Type the password. Score, grade and time to crack update as you type.
- See which of the five checks (16 characters, uppercase, lowercase, numbers, symbols) are missing, plus tips.
- Press “Check if it was leaked” to match it against breaches and get the final score.
Strength: zxcvbn-ts (MIT) · Breach data: Have I Been Pwned (CC BY 4.0)
Tools
Play together
Make a group scoreboardFAQ
How is password strength calculated?
With zxcvbn-ts, the TypeScript port of Dropbox’s zxcvbn. It splits the password into common words, names, dates, keyboard patterns and repeats, and estimates how many guesses an attacker needs. The score is that number’s power of ten × 5 (max 100).
I used upper case, numbers and symbols — why is my score low?
Patterns like word + year + “!” (Summer2024!) are among the first things attackers try. Length and unpredictability matter far more than character types.
What does time to crack assume?
A fast offline attack at 10 billion guesses per second after a hash leak. Real login pages throttle attempts, but planning for the worst case is safer.
Is my password sent anywhere?
Strength is calculated entirely on your device. Only when you press “Check if it was leaked” do the first 5 characters of its SHA-1 hash go to Have I Been Pwned.
What score is safe?
Aim for 70 (Solid) or more. Four or more unrelated words, 16+ characters, usually score above 90 (Fortress).