Password strength check
Drop a password in and get a real report: entropy estimate, which weak patterns it contains, and how long it would take to crack — all calculated on your device. The breach lookup is optional and needs your explicit OK.
Runs entirely in your browser. Nothing is uploaded or stored.
Optional: check whether this password has appeared in a public data breach. This is the only feature that uses the network.
What will be sent: the first 5 characters of this password's SHA-1 hash (e.g. 21BD1). Your password itself never leaves this page, and the answer is matched locally. Continue only if you're comfortable with that.
FAQ
Is my password sent anywhere?
Not by default. Strength analysis, common-password matching and pattern detection all run locally — disconnect and it still works. The breach check is a separate button: it sends only the first 5 characters of the password's SHA-1 hash.
How can a server check my password without seeing it?
It's called k-anonymity: the server returns every hash suffix starting with those 5 characters (a few hundred), and the comparison happens here. The server learns nothing about which one is yours.
Why does it say my long password is weak?
Because entropy is not only length. 'password12345' is long and still cracked instantly — it's a known password plus a predictable suffix, so its real search space is tiny.
Are the cracking times exact?
No, they're estimates. Each attack scenario assumes a different speed (rate-limited login, unthrottled login, a single GPU, a GPU cluster) — the honest answer is 'this order of magnitude', not a precise number.
Should I type my real password here?
That's your call. The page is built so it never leaves your device, and you can verify that by disconnecting first. If you're still unsure, test a password you already know is bad — the report is the same.