About this tool
This checker estimates password strength using entropy (a measure of unpredictability based on character variety and length) combined with pattern detection for common weaknesses — repeated characters, sequential runs, and common substrings. Everything runs locally in your browser; nothing you type is ever sent anywhere.
How to use the Password Strength Checker
- Type a password into the field — use "Show" to reveal it if you want to double-check what you typed.
- Read the strength bar and label — it updates as you type.
- Check the flagged issues below for specific weaknesses to fix.
What this tool actually measures
Entropy estimates how many attempts a brute-force guesser would need on average, based on how large a character pool your password draws from (lowercase only, versus lowercase+uppercase+numbers+symbols) and how long it is. On top of that raw estimate, this checker specifically penalizes patterns that make a password easier to guess than its entropy alone would suggest — sequential runs like "abcdef" or "12345," repeated characters like "aaaa," and a handful of extremely common passwords and substrings like "password" or "qwerty."
Things to watch out for
A high score here reflects resistance to common guessing techniques, not a guarantee against every attack — it can't know whether this exact password has already been exposed in a data breach, which is a completely separate risk from strength. A password that's strong but reused across multiple accounts is still vulnerable if any one of those accounts gets breached. For truly critical accounts, a password manager that generates and stores unique, random passwords remains the strongest practical defense — try the Password Generator for creating those.
Frequently asked questions
No. The entire check runs as JavaScript in your browser — nothing you type is ever transmitted, logged, or stored anywhere, including by this site.
Length alone doesn't guarantee strength. A long password built from a repeated pattern, a common phrase, or sequential characters (like "abcdefgh" or "password123") is still easy to guess, so this checker also looks for those patterns rather than scoring on length alone.
No score can guarantee that. This tool estimates resistance to common guessing techniques (dictionary words, patterns, brute force), but it can't account for whether a password has already been exposed in a data breach — a strong-looking but previously leaked password is still unsafe to reuse.