Measure how strong a password or passphrase really is. This tool estimates entropy, projects how long an offline attacker would need to crack it, and flags the weak patterns attackers exploit first. Everything runs in your browser — nothing you type is sent anywhere.
Start typing to see strength analysis.
Privacy: analysis runs entirely in your browser. Your input is never transmitted, logged, or stored.
Strength is driven by entropy — the number of bits of unpredictability in a password. Entropy grows with length and with the size of the character set used, so a long passphrase usually beats a short but complex string. The crack-time estimate assumes a well-resourced offline attacker guessing roughly 100 billion hashes per second against a fast hash. Common words, repeats, and keyboard sequences are penalized because attackers try those dictionaries first. For enterprise password policy guidance, talk to our team.
No. The entire analysis runs locally in your browser using JavaScript. Your input is never transmitted over the network, logged, or stored. You can confirm this by disconnecting from the internet — the tool still works.
Entropy measures unpredictability in bits. Each additional bit doubles the number of guesses an attacker needs. As a rough guide, under 40 bits is weak, 60 bits is reasonable, and 80+ bits is strong against offline attacks.
Usually, yes. A passphrase of four or more random words is long enough to reach high entropy while remaining memorable, whereas short complex passwords are both hard to remember and often too short to resist offline cracking.
It is a planning estimate, not a guarantee. Real crack time depends on the hashing algorithm, hardware, and whether the password appears in breach dictionaries. Treat the figure as a relative indicator of strength rather than an exact number.