Password Generator
Generate strong random passwords with your own length and character rules.
See how strong a password really is, without sending it anywhere.
Nothing is sent, stored or logged. Even so, a sensible habit is to test something similar rather than a live password.
Crack times are order-of-magnitude guides. Real speed depends on how the site stored the password: a slow algorithm such as bcrypt or Argon2 makes guessing far harder than a plain hash.
Password Strength Checker estimates how hard a password would be to guess, and explains why. The headline figure is entropy in bits, which measures unpredictability: each extra bit doubles the number of guesses an attacker needs on average.
Entropy alone is not the whole story, so the checker also looks for the patterns that make a password far weaker than its length suggests. Dictionary words, keyboard runs like qwerty, sequences like 1234, repeated characters, years, and the substitutions everyone uses, such as zero for o and three for e, are all recognised. A password that looks complicated but is a common word with predictable substitutions is a password attackers crack first, because their tools try exactly that.
Nothing you type is transmitted, stored or logged. The analysis runs entirely in the page, which is the only honest way to offer this: a strength checker that sends your password to a server is asking you to do the exact thing password advice tells you never to do.
The password strength checker is used by writers, developers, students, marketers and anyone else who needs the job done once without installing software. Common cases include:
The analysis runs entirely in your browser: nothing is sent, stored or logged, and closing the tab discards it. That said, a sensible habit is never to type a live password into any web page. Test something structurally similar instead.
It measures unpredictability in bits, where each bit doubles the guesses needed. Under about 50 bits is weak against a determined attacker, 70 to 80 is solid for most accounts, and over 100 is beyond brute force with foreseeable hardware.
Because complexity and unpredictability are not the same thing. P@ssw0rd1 uses four character types and is among the first things any cracking tool tries, since the substitutions are completely standard. Length and genuine randomness beat decorated dictionary words every time.
Usually, yes. Four or five random words are easy to remember and have more entropy than a short string of mixed characters, provided the words are chosen randomly rather than forming a quotation or a phrase.
They are order-of-magnitude guides, not predictions. Real speed depends on how the site stored the password: a slow algorithm such as bcrypt or Argon2 makes guessing orders of magnitude harder than a plain hash. Several speeds are shown for that reason.
Not reusing passwords. A strong password reused across sites is compromised everywhere as soon as one of them leaks. A password manager removes the need to remember or reuse anything, which is a bigger win than any amount of added complexity.
If the password strength checker is not quite what you need, these other free tools solve closely related problems.
Generate strong random passwords with your own length and character rules.
Generate cryptographic hashes of text, computed in your browser.
Generate cryptographically random UUIDs in bulk, with format options.
Generate a Content Security Policy header directive by directive, with explanations.
Build security header configuration for Apache, nginx, Netlify or Vercel.