Password Strength Checker

Check how strong a password actually is — entropy, common-password matches, and predictable patterns

Nothing you type here is sent anywhere — the check runs entirely in your browser. That said, avoid typing a password you actually use for something important into any strength checker, this one included — treat results as a general guide, not a guarantee.

About this tool

The Password Strength Checker estimates how hard a password actually is to guess — not just whether it satisfies a length-and-symbol-count rule. It computes a charset-size^length entropy estimate (the same basic approach most strength meters use), then applies penalties for the specific patterns that make a password far weaker than its raw entropy suggests: matching one of the most commonly leaked passwords, sequential runs (abcd, 1234), repeated characters (aaaa), and keyboard-adjacent walks (qwerty, asdf). This matters because raw entropy alone would rate something like 'qwertyuiop1234' as reasonably strong — it's 14 characters mixing letters and numbers — when it's actually trivially guessable because every attacker's wordlist already contains exactly this kind of keyboard-walk pattern.

When to use it

  • →Checking whether a password you're about to set is actually strong, not just long
  • →Understanding why a password that 'looks complex' might still be weak (keyboard patterns, sequences)
  • →Teaching or demonstrating what makes one password meaningfully stronger than another
  • →Spot-checking a generated or memorized passphrase before using it somewhere important

Tips

  • ◆A password that scores well here but that you've used anywhere else before is still compromised if that other site ever leaked — this tool has no way to check real-world breach databases, it only evaluates the string itself.
  • ◆Length matters more than complexity rules once you're past a reasonable floor — a 16-character lowercase phrase can out-entropy an 8-character password stuffed with symbols.
  • ◆Treat the common-password list here as a small, illustrative sample, not an exhaustive breach database check — not matching the list doesn't mean a password has never been leaked elsewhere.

Frequently asked questions

Does this check my password against real breach databases like Have I Been Pwned?

No — that would require sending your password (or a hash of it) to an external service, which this tool deliberately never does. It only checks against a small, illustrative list of extremely common passwords and a few structural weaknesses (sequences, repeats, keyboard patterns), entirely offline.

Why did a long, random-looking password still get flagged?

Check the warnings list — a password can be long and still contain a sequential run, a repeated block, or a keyboard-walk substring hiding inside otherwise-random-looking characters. Any of those meaningfully reduce how hard the password actually is to guess, even though the raw character count looks strong.

Is it safe to type a real password into this tool?

The check runs entirely in your browser with no network calls, so nothing is transmitted anywhere. That said, as a general safety habit, avoid typing a password you actually rely on into any web tool, including this one — test with a similar-but-different string if you want to gauge a pattern's strength without exposing the real thing.

Related tools

🥷 ToolNinja