Skip to content
JustTools

Password Strength Checker

See how long a password would take to crack, what attackers would spot in it — names, dates, keyboard patterns, look-alike swaps — and whether it has leaked in a data breach.

Runs in your browser Free · no sign-up

At a glance

  • Uses zxcvbn, the password-strength estimator developed at Dropbox, which models how real attackers guess instead of just counting symbols.
  • Recognises tens of thousands of common passwords, English words, first names and surnames, plus common Indian names and words such as Rahul, Priya, Sairam or Jaishreeram.
  • Spots keyboard patterns (qwerty), sequences (1234, abcd), repeats, dates and years, and look-alike swaps like P@ssw0rd.
  • Shows the time to crack in four realistic situations, from a rate-limited login page to a stolen database cracked on GPUs.
  • The optional data-breach check uses Have I Been Pwned’s k-anonymity API: only the first 5 characters of the password’s SHA-1 hash are sent, never the password.
  • Everything else runs in your browser; the password is never stored or sent anywhere.

Step by step

How to check password strength

  1. 1

    Type the password

    Type or paste it into the box. Use the eye button to show or hide it.

  2. 2

    Read the rating

    The meter shows Very weak to Very strong, with the estimated number of guesses needed.

  3. 3

    See why

    Check the time to crack, the checklist and What an attacker would notice.

  4. 4

    Check for leaks

    Click Check now to see if it has appeared in a data breach. If it has, stop using it.

Features

Everything you need, nothing you don’t

Realistic, not naive

“P@ssw0rd123” ticks every box on most sites — here it’s rated weak, because attackers try exactly those swaps first.

Time to crack

From a login page that blocks repeated tries to a leaked database attacked with graphics cards.

What gives it away

See each part an attacker would recognise: a common password, a name, a year, a keyboard walk.

Has it leaked?

Compare against hundreds of millions of passwords exposed in data breaches, without revealing yours.

Clear advice

Specific tips to make it stronger — and a link to generate a truly random one.

Private

Nothing you type is saved or sent. Works offline once loaded (except the optional breach check).

What makes a password strong

Length and randomness beat complexity. A random 4–5 word passphrase like “tiger-lamp-orbit-seven” is far stronger than “Rahul@1990”, and easier to remember. Names, birthdays, cricket players, cities and keyboard patterns are the first things cracking tools try — with or without @ for a and 0 for o.

Just as important: never reuse a password. When one site leaks, attackers try the same email and password everywhere else. Use a password manager to store a different random password for every account, and turn on two-factor authentication for email, banking and UPI apps.

Time to crack, explained

SituationGuesses per secondNeeds
Login page with rate limiting100 per hourAny password that isn’t very common
Login page without limits10At least a fair password
Leaked database, bcrypt or similar10,000A strong password
Leaked database, MD5 or similar, GPUs10 billionA very strong, random password

FAQ

Frequently asked questions

Is it safe to type my password here?

Yes. The strength check runs entirely in your browser, and the password is never stored or sent. If you prefer, test a password that follows the same pattern as yours instead of the real one.

How does the data-breach check work without sending my password?

Your browser computes the SHA-1 hash of the password and sends only its first five characters to Have I Been Pwned. The service returns every leaked hash starting with those characters (with random padding), and the match is found on your device. The password and its full hash never leave it.

Why is my password with symbols rated weak?

Because the rest of it is predictable. Attackers’ tools try common words with capitals, numbers, years and symbol swaps first, so “Password@123” falls in seconds. Randomness and length matter far more than symbols.

How long should a password be?

At least 12 characters for everyday accounts, and 15 or more — or a passphrase of four to five random words — for email, banking and your password manager.

What does “Found in data breaches” mean?

The exact password appears in lists of passwords leaked from hacked websites. Attackers try these lists first, so don’t use it anywhere, even if it looks strong.

How is this different from the strength bar on websites?

Most sites only check length and character types. This tool estimates the number of guesses a real attacker would need, recognising common passwords, names, dates and patterns.

Keep going

Browse every tool

Last updated Report a problem or suggest a feature