Password Strength Analyser
This runs entirely in the page. There is no request to send it in, no storage, nothing in the address bar and no record after you close the tab — but do treat any password you have typed into any website as one to change.
Very weak · about 2 bits · cracked instantly
The case worth planning for: the hashes are already taken, nothing rate-limits anything, and the hash was cheap to compute — MD5, SHA-1, a bare SHA-256.
Time to guess
instantly
at 10,000,000,000 guesses a second — a stolen database, hashed fast. Half of a 2-bit space, which is where a password is found on average.
- Guesses a second assumed10,000,000,000
- Search space2^2
- Patterns found2
How this was worked out
- Symbols in the poollower case 26 + upper case 26 + digits 10 + symbols 33 = 95
- Bits per characterlog2(95) = 6.57
- Before any penalty11 × 6.57 = 72.3 bits
- After the patterns foundcapped at 8, −6 = 2 bits
- Time to guess2^1 ÷ 10,000,000,000 guesses a second = instantly
Where the bits come from
- Lower case+26
- Upper case+26
- Digits+10
- Symbols+33
11 characters drawn from 95 possible symbols is 72 bits before any penalty.
Patterns crackers try first
Breach-list passwordcapped at 8 bits
Cracking software starts from leaked password lists, so anything on one falls in the first second no matter how it is dressed up.
Adjacent keyboard keysnot found
Alphabet or digit runnot found
Repeated characternot found
Four-digit year−6 bits
Appended years span roughly 1900 to 2099, which is a couple of hundred candidates rather than the ten thousand four free digits would be.
What would help
- Pick something that is not in any breach list.
- Use at least 12 characters — length matters more than symbols.
The bit count assumes the attacker knows exactly how the password was built. It is length times log2 of the pool, which is the entropy of a password a machine drew uniformly from that pool and an upper bound on anything a person composed. Four dictionary words joined by hyphens score close to two hundred bits here and are worth about forty, because the attacker guesses words rather than characters — the passphrase generator does that arithmetic properly. A rule you applied is a rule an attacker applies too.
A score is not a promise. The number here describes how long guessing would take, and guessing is not how most passwords are lost — reuse across sites, a phishing page and malware on the machine all defeat a very strong password without attacking it. The three attacker rates are orders of magnitude picked to bracket the range, not measurements of any particular hardware. A password manager and multi-factor authentication move the needle further than any extra character can.
Rules describe the alphabet, not the choice
Most signup forms judge a password by what characters it contains. That test is easy to satisfy and tells an attacker almost nothing, because guessing software does not walk the alphabet in order — it works from lists of what people have actually chosen, then applies rules that capitalise a first letter, swap an a for an @, and stick a year on the end. A password assembled the way the form asked is exactly the shape those rules produce.
So this analyser does two things in sequence. It measures how large the search would be if the password were random, and then it subtracts for each way the password announces that it was not.
Where the bit count comes from
The character pool is the sum of the classes present: 26 for lower case, 26 for upper, 10 for digits and 33 for the printable ASCII punctuation, giving 95 when all four appear. Raw entropy is the length multiplied by the base-two logarithm of that pool, so twelve characters from the full set is about 79 bits before anything is taken away.
Five deductions follow. A password found on the built-in list of common choices is capped at 8 bits outright, because it is looked up rather than searched for. A run of adjacent keyboard keys costs 12 bits, an alphabetical or numeric run 10, a character repeated three times or more 8, and anything shaped like a four-digit year 6. The verdict bands sit at 28, 40, 60 and 80 bits.
What the time figure assumes
The estimate quoted is for an offline attack at ten billion guesses a second, against half the search space, which is the average a random target takes to reach. That rate is a stand-in for an attacker with a stolen database and their own hardware, and it is deliberately pessimistic — the point is the order of magnitude, not the number of hours.
How fast a real attack runs depends on how the site stored the password, which this tool cannot know. An unsalted SHA-1 column falls far faster than the figure here; bcrypt at a high cost factor, or Argon2id, is slower by many orders of magnitude. A guess against a live login form is slower still, and usually stopped by rate limiting long before entropy matters.
Where it is more generous than reality
The built-in list of common passwords holds about sixty entries. Real cracking dictionaries hold hundreds of millions, assembled from every breach of the last fifteen years, so a password this tool has never heard of may still be sitting in one. Five pattern families are checked here against the thousands of mangling rules a serious rig applies.
It also knows nothing about you. Your surname, your child’s name, your street, the team you support and the year you graduated are all high-value guesses to somebody targeting you specifically, and all of them read here as ordinary letters. Nothing typed into the box is sent anywhere, stored, or kept after the tab closes — but a password you have typed into any web page is one worth changing regardless.
Acting on a poor reading
The reliable fix for a weak score is to stop inventing passwords. A generated value has no story behind it for a rule set to reconstruct, and a password manager removes the only reason people invent them, which is having to remember the result.
Two accounts earn more care than the rest: the mailbox that receives every reset link, and the vault that holds everything else. Both are routes into every other account you own. Where a second factor is offered, switching it on defeats an attacker who already has the password — which is the situation no amount of entropy addresses.
When a long password still scores badly
Why does a long password sometimes score instantly?
Because length cannot rescue a password that is already on a list. Once the value is recognised as a common choice the score is capped at 8 bits, which is the honest reading: the attacker looks it up in the first second rather than searching for it.
My password manager disagrees with this score. Which is right?
Probably neither exactly. Different estimators use different dictionaries and different penalties, so they routinely differ by a band. Treat any of them as a rough gauge, and act on the specific weakness named rather than on the label attached to it.
Does adding a symbol help more than adding characters?
No, and it is not close. Adding one symbol to a twelve-character password widens the pool from 62 to 95, worth about six bits. Adding four more characters to the same password is worth roughly twenty-four. Length is the cheapest strength available.
Should I use this on a password I actually use?
It is safe in the sense that the analysis runs in your browser and nothing is transmitted, but the safer habit is to test a password of the same shape instead. Save the real one for a password manager, which never needs it analysed.
Are periodic password changes a good idea?
Not on a schedule. Forced rotation pushes people towards a stem and a counter, which is easier to guess than what they started with. Change a password when there is a reason: a breach, a shared device, a suspicion.
What makes a passphrase strong?
The number of words and the size of the list they were drawn from, not the grammar. Four words picked at random from a long word list beats a memorable sentence, because a sentence is drawn from the far smaller space of things people actually say.