Password checker
Type a password and we instantly tell you how strong it is: strength, entropy in bits, dangerous patterns, how long it would take to crack, and whether it appears in known breaches. All analysis happens in your browser.
Your password never leaves your browser
Start typing to see the analysis. Nothing you type leaves your browser.
Technical detail
- Length
- 0 characters
- Estimated entropy
- 0 bits
Character types:
Estimated time to crack it
Brute-force estimate per attack scenario. It is indicative: a known pattern can fall much sooner.
Online attack (rate limited)
—
100 guesses/hour — a protected login form.
Fast offline attack (GPU)
—
10 billion guesses/second — a leaked hash cracked with powerful hardware.
Warnings
How to make it stronger
Has it appeared in a breach?
Optional check against the Pwned Passwords database (>800 million leaked passwords) using k-anonymity: your browser computes the SHA-1 hash and sends ONLY its first 5 characters. Your password and the full hash never leave here.
Indicative estimate based on good practice. Real crack time depends on the attacked system and hardware. 100% local computation, nothing stored.
Password checker
Measure your password strength without it leaving your browser
Most security breaches start with a weak or reused password. This tool tells you instantly and for free how strong your password is, which dangerous patterns it contains and how long an attacker would take to crack it, without sending your password to any server.
How it works
Real-time local analysis. As you type, we compute — in your own browser — entropy (bits of randomness), length, character types and predictable patterns: sequences (abc, 123), keyboard runs (qwerty), repeats, years and dictionary words.
A clear verdict. A colour bar and a label from Very weak to Very strong, plus a crack-time estimate for two scenarios: a rate-limited online attack and a fast offline GPU attack.
Actionable advice. We tell you exactly what to change to make it stronger: more length, a mix of upper/lowercase/digits/symbols, or switching to a passphrase.
Privacy first
- Your password never leaves your browser. The strength meter runs 100% locally: it is never written to disk, stored or sent to any server.
- No account, no quota, no tracking. You do not need to sign up to use it.
- Breach check via k-anonymity. If you press the button to check whether your password appears in Pwned Passwords (over 800 million leaked passwords), your browser computes the SHA-1 hash and sends only the first 5 characters of that hash. Neither your password nor the full hash ever leaves your device.
What makes a password strong
1. Length. The single most important factor: aim for 12-16 characters or more.
2. Randomness. Avoid words, names, dates and keyboard patterns.
3. Passphrases. Four or five random, unrelated words are easy to remember and very hard to guess.
4. Uniqueness. Never reuse the same password across services.
5. A password manager generates and stores unique passwords for you.
Want continuous breach monitoring and best practices for your whole team? Sign up free at OCIRIA Security.