What this does
Type a password and get a score from 0 to 4, an estimate of how many guesses it would take, how long that takes under four attack scenarios, and specific feedback about what makes it weak. The estimate uses zxcvbn, which models how real attackers guess instead of just counting character types.
What it detects
- Common passwords and names, English words, and Wikipedia terms.
- Substitutions like
p@ssw0rdand reversed words. - Keyboard walks such as
qazwsx, repeats likeabcabc, and sequences like1234. - Dates and years.
"How it was read" shows how the password was split into patterns. Each pattern is a shortcut an attacker could take.
Crack-time scenarios
- Online with throttling: 100 guesses per hour, a rate-limited login form.
- Online without throttling: 10 guesses per second.
- Offline with a slow hash: 10,000 guesses per second, such as bcrypt.
- Offline with a fast hash: 10 billion guesses per second, such as unsalted MD5 on GPUs.
These are estimates, not guarantees. A password found in a breach is weak no matter its score.
Limits
Only the first 256 characters are analyzed. The estimator and its dictionaries (about 1.7 MB, 850 KB compressed) load the first time you type, in a background worker.
Privacy
The password never leaves your browser. It is analyzed in a Web Worker on this page, not sent to any server, and not stored or put in the URL. You can test it offline once the page has loaded.