Password Strength Checker
Check how strong a password actually is — entropy, common-password matches, and predictable patterns
About this tool
The Password Strength Checker estimates how hard a password actually is to guess — not just whether it satisfies a length-and-symbol-count rule. It computes a charset-size^length entropy estimate (the same basic approach most strength meters use), then applies penalties for the specific patterns that make a password far weaker than its raw entropy suggests: matching one of the most commonly leaked passwords, sequential runs (abcd, 1234), repeated characters (aaaa), and keyboard-adjacent walks (qwerty, asdf). This matters because raw entropy alone would rate something like 'qwertyuiop1234' as reasonably strong — it's 14 characters mixing letters and numbers — when it's actually trivially guessable because every attacker's wordlist already contains exactly this kind of keyboard-walk pattern.
When to use it
- →Checking whether a password you're about to set is actually strong, not just long
- →Understanding why a password that 'looks complex' might still be weak (keyboard patterns, sequences)
- →Teaching or demonstrating what makes one password meaningfully stronger than another
- →Spot-checking a generated or memorized passphrase before using it somewhere important
Tips
- ◆A password that scores well here but that you've used anywhere else before is still compromised if that other site ever leaked — this tool has no way to check real-world breach databases, it only evaluates the string itself.
- ◆Length matters more than complexity rules once you're past a reasonable floor — a 16-character lowercase phrase can out-entropy an 8-character password stuffed with symbols.
- ◆Treat the common-password list here as a small, illustrative sample, not an exhaustive breach database check — not matching the list doesn't mean a password has never been leaked elsewhere.
Frequently asked questions
Does this check my password against real breach databases like Have I Been Pwned?
No — that would require sending your password (or a hash of it) to an external service, which this tool deliberately never does. It only checks against a small, illustrative list of extremely common passwords and a few structural weaknesses (sequences, repeats, keyboard patterns), entirely offline.
Why did a long, random-looking password still get flagged?
Check the warnings list — a password can be long and still contain a sequential run, a repeated block, or a keyboard-walk substring hiding inside otherwise-random-looking characters. Any of those meaningfully reduce how hard the password actually is to guess, even though the raw character count looks strong.
Is it safe to type a real password into this tool?
The check runs entirely in your browser with no network calls, so nothing is transmitted anywhere. That said, as a general safety habit, avoid typing a password you actually rely on into any web tool, including this one — test with a similar-but-different string if you want to gauge a pattern's strength without exposing the real thing.