>_devtools

Password Strength Checker

Estimate password strength with zxcvbn: guesses, crack-time estimates, and specific feedback. Runs locally.

What this does

Type a password and get a score from 0 to 4, an estimate of how many guesses it would take, how long that takes under four attack scenarios, and specific feedback about what makes it weak. The estimate uses zxcvbn, which models how real attackers guess instead of just counting character types.

What it detects

  • Common passwords and names, English words, and Wikipedia terms.
  • Substitutions like p@ssw0rd and reversed words.
  • Keyboard walks such as qazwsx, repeats like abcabc, and sequences like 1234.
  • Dates and years.

"How it was read" shows how the password was split into patterns. Each pattern is a shortcut an attacker could take.

Crack-time scenarios

  • Online with throttling: 100 guesses per hour, a rate-limited login form.
  • Online without throttling: 10 guesses per second.
  • Offline with a slow hash: 10,000 guesses per second, such as bcrypt.
  • Offline with a fast hash: 10 billion guesses per second, such as unsalted MD5 on GPUs.

These are estimates, not guarantees. A password found in a breach is weak no matter its score.

Limits

Only the first 256 characters are analyzed. The estimator and its dictionaries (about 1.7 MB, 850 KB compressed) load the first time you type, in a background worker.

Privacy

The password never leaves your browser. It is analyzed in a Web Worker on this page, not sent to any server, and not stored or put in the URL. You can test it offline once the page has loaded.