Pwned Password Check 한국어

Password Strength Checker

Type a password to see its security score (0–100) and time to crack. For example, Summer2024! has upper and lower case, a number and a symbol, yet it is a common pattern: 38 (Shaky) and less than a second on a fast rig. Everything is calculated on your device.

Password breach & strength check

Calculated on this device as you type

-

Time to crack this password: -

Your password is SHA-1 hashed on this device and only the first 5 characters of the hash go to Have I Been Pwned (k-anonymity). The password and its full hash are never sent or stored.

Group security scoreboard

Compare security scores with friends, coworkers or family. “Find the weak link” unlocks at 3 people.

The scoreboard only stores your name, security score and leaked yes/no. Never your password, its hash or the breach count.

Score bands and grades

GradeScoreMeaning
Fortress90–100Centuries even for fast cracking rigs
Solid70–89Hard to crack with realistic attacks
Fair45–69Survives slow hashes, at risk with fast ones
Shaky20–44Falls quickly to dictionary and pattern attacks
Wide open0–19On attackers’ first-try lists
Leaked≤ 10Found in breaches — change it now, whatever its length

Score = estimated guesses as a power of ten × 5; 1020 guesses or more is 100. Time to crack assumes a fast offline attack at 10 billion guesses per second.

How attackers crack weak passwords

What makes a strong password

How to use the password strength checker

  1. Type the password. Score, grade and time to crack update as you type.
  2. See which of the five checks (16 characters, uppercase, lowercase, numbers, symbols) are missing, plus tips.
  3. Press “Check if it was leaked” to match it against breaches and get the final score.

Strength: zxcvbn-ts (MIT) · Breach data: Have I Been Pwned (CC BY 4.0)

Tools

Play together

Make a group scoreboard

FAQ

How is password strength calculated?

With zxcvbn-ts, the TypeScript port of Dropbox’s zxcvbn. It splits the password into common words, names, dates, keyboard patterns and repeats, and estimates how many guesses an attacker needs. The score is that number’s power of ten × 5 (max 100).

I used upper case, numbers and symbols — why is my score low?

Patterns like word + year + “!” (Summer2024!) are among the first things attackers try. Length and unpredictability matter far more than character types.

What does time to crack assume?

A fast offline attack at 10 billion guesses per second after a hash leak. Real login pages throttle attempts, but planning for the worst case is safer.

Is my password sent anywhere?

Strength is calculated entirely on your device. Only when you press “Check if it was leaked” do the first 5 characters of its SHA-1 hash go to Have I Been Pwned.

What score is safe?

Aim for 70 (Solid) or more. Four or more unrelated words, 16+ characters, usually score above 90 (Fortress).