Password Strength Checker
See how long a password would take to crack, what attackers would spot in it — names, dates, keyboard patterns, look-alike swaps — and whether it has leaked in a data breach.
At a glance
- Uses zxcvbn, the password-strength estimator developed at Dropbox, which models how real attackers guess instead of just counting symbols.
- Recognises tens of thousands of common passwords, English words, first names and surnames, plus common Indian names and words such as Rahul, Priya, Sairam or Jaishreeram.
- Spots keyboard patterns (qwerty), sequences (1234, abcd), repeats, dates and years, and look-alike swaps like P@ssw0rd.
- Shows the time to crack in four realistic situations, from a rate-limited login page to a stolen database cracked on GPUs.
- The optional data-breach check uses Have I Been Pwned’s k-anonymity API: only the first 5 characters of the password’s SHA-1 hash are sent, never the password.
- Everything else runs in your browser; the password is never stored or sent anywhere.
Step by step
How to check password strength
- 1
Type the password
Type or paste it into the box. Use the eye button to show or hide it.
- 2
Read the rating
The meter shows Very weak to Very strong, with the estimated number of guesses needed.
- 3
See why
Check the time to crack, the checklist and What an attacker would notice.
- 4
Check for leaks
Click Check now to see if it has appeared in a data breach. If it has, stop using it.
Features
Everything you need, nothing you don’t
Realistic, not naive
“P@ssw0rd123” ticks every box on most sites — here it’s rated weak, because attackers try exactly those swaps first.
Time to crack
From a login page that blocks repeated tries to a leaked database attacked with graphics cards.
What gives it away
See each part an attacker would recognise: a common password, a name, a year, a keyboard walk.
Has it leaked?
Compare against hundreds of millions of passwords exposed in data breaches, without revealing yours.
Clear advice
Specific tips to make it stronger — and a link to generate a truly random one.
Private
Nothing you type is saved or sent. Works offline once loaded (except the optional breach check).
What makes a password strong
Length and randomness beat complexity. A random 4–5 word passphrase like “tiger-lamp-orbit-seven” is far stronger than “Rahul@1990”, and easier to remember. Names, birthdays, cricket players, cities and keyboard patterns are the first things cracking tools try — with or without @ for a and 0 for o.
Just as important: never reuse a password. When one site leaks, attackers try the same email and password everywhere else. Use a password manager to store a different random password for every account, and turn on two-factor authentication for email, banking and UPI apps.
Time to crack, explained
| Situation | Guesses per second | Needs |
|---|---|---|
| Login page with rate limiting | 100 per hour | Any password that isn’t very common |
| Login page without limits | 10 | At least a fair password |
| Leaked database, bcrypt or similar | 10,000 | A strong password |
| Leaked database, MD5 or similar, GPUs | 10 billion | A very strong, random password |
FAQ
Frequently asked questions
Is it safe to type my password here?
How does the data-breach check work without sending my password?
Why is my password with symbols rated weak?
How long should a password be?
What does “Found in data breaches” mean?
How is this different from the strength bar on websites?
Keep going
Related tools
Password Generator
Generate strong, random passwords, memorable passphrases and PINs with a cryptographically secure generator. Free, instant and private — nothing is stored.
SSL Checker
Check any website’s SSL certificate: expiry date and days left, issuer, covered domains, revocation and CAA, plus a live HTTPS test from your browser.
Image Steganography Tool
Hide a secret message or file inside an image, protected with a password, and reveal hidden messages from PNG images. Free and private — no upload.
DNS Lookup
Free DNS lookup: check A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records of any domain, see SPF and DMARC, and do reverse DNS for an IP address.
PPK to PEM Converter
Convert a PuTTY .ppk private key to PEM or OpenSSH format online, with or without a passphrase. Supports PPK v2 and v3, RSA, ECDSA and Ed25519. No upload.
PEM to PPK Converter
Convert a PEM or OpenSSH private key (id_rsa, AWS .pem) to a PuTTY .ppk file online — PPK v3 or v2, with an optional passphrase. Free, private, no upload.
Last updated Report a problem or suggest a feature