Password strength checker
How strong is your password, really? Type it below to see how many guesses it would take to crack, which parts give it away, and whether it shows up in breach lists.
Add your name, email or pet's name to catch personal words
Start typing. The dial reads the estimated number of guesses as a power of ten: 3 on the dial is a thousand guesses, 12 is a trillion.
How this checker scores a password
Attackers don't guess one character at a time. They start with lists of leaked passwords, then dictionary words with capitals, years and a symbol stuck on the end, then keyboard runs, dates and names, and only fall back to pure brute force at the very end.
So the checker works the same way. zxcvbn-ts, a maintained TypeScript port of Dropbox's zxcvbn estimator, splits your password into the cheapest set of known patterns and multiplies their guess counts. The dial shows the result on a log scale, because a password that takes 1012 guesses is not twice as strong as one that takes 106: it's a million times stronger.
Crack time depends on a second thing you don't control: how the site stores your password. A login form that locks after a few tries makes almost anything slow to guess online. A leaked database hashed with MD5 lets a single GPU test tens of billions of guesses a second. That's why we show four scenarios instead of one number.
What leaves your device
| Password you type | Never leaves |
| Strength score and patterns | Computed locally |
| Personal words box | Never leaves |
| Breach check (on click) | First 5 hex chars of SHA-1 |
| Page-view analytics | Page URL only, no inputs |
Details on the privacy page. Curious what attackers try first? See the 200 most common passwords. Need a new password instead? Use the password generator or a diceware passphrase.
Password strength table: length vs character types
How long a randomly generated password survives a leaked fast-hash database (about 100 billion guesses per second on one high-end GPU). Human-chosen passwords fall much faster; that's what the checker above measures.
| Length | Numbers only | Lowercase | Upper + lower | + numbers | + symbols |
|---|---|---|---|---|---|
| 6 | instantly | instantly | instantly | instantly | 6.9 seconds |
| 8 | instantly | 2.1 seconds | 8.9 minutes | 36 minutes | 17 hours |
| 10 | instantly | 24 minutes | 17 days | 3.2 months | 17 years |
| 12 | 10 seconds | 11 days | 1.2 centuries | 1 thousand years | 151 thousand years |
| 14 | 17 minutes | 20 years | 335 thousand years | 3.9 million years | 1.3 billion years |
| 16 | 1.2 days | 14 thousand years | 906 million years | 15 billion years | about 10¹³ years |
| 18 | 3.8 months | 9.3 million years | about 10¹² years | about 10¹³ years | about 10¹⁷ years |
Worst case, i.e. trying every combination. Change the attack speed on the crack time calculator. Want one of the green cells? The password generator makes them.
Password strength: questions people ask
Is it safe to type my password into this checker?
The strength check runs entirely in your browser with the open-source zxcvbn-ts library. The password is not sent to our server, not logged and not stored. The only network request tied to a password is the optional breach check, which sends the first 5 characters of its SHA-1 hash to Have I Been Pwned, never the password. Even so, the cautious habit is to test a password that is similar in structure to your real one.
How does the checker decide how strong my password is?
It estimates how many guesses a smart attacker would need. zxcvbn-ts looks for common passwords, dictionary words, names, keyboard runs like qwerty, repeats, sequences, dates and l33t swaps, then finds the cheapest way to build your password from those pieces. Anything left over is priced as random characters.
What do the scores mean?
The score is a 0–4 summary of the guess estimate: under a thousand guesses is very weak (0), under a million weak (1), under a hundred million fair (2), under ten billion strong (3), and more than that very strong (4). For an important account, aim for a 4 and a long password.
Why is my crack time different on other sites?
Many checkers multiply character-set size by length and assume every character is random. That overrates passwords like Summer2024! because a real attacker tries words, years and a trailing symbol first. We show both figures on the entropy calculator so you can see the gap.
What is a good password length?
NIST SP 800-63B requires verifiers to accept at least 64 characters and sets a minimum of 8, with 15 recommended when a password is the only factor. In practice, a random 16-character password or a five-to-six-word passphrase is strong for any personal account.
How do I check if my password is safe?
Type it into the checker above: it estimates the guesses needed, shows the time to crack under four attack scenarios and names the patterns that weaken it. Then press the breach-check button to see whether the exact password appears in Have I Been Pwned data. A safe password scores 4/4, has not been breached, and is used on only one site.
How do I check if my password has been hacked?
Use the breach check on this page or on the dedicated breach check page. It compares your password with the Pwned Passwords collection of hundreds of millions of leaked passwords, sending only the first 5 characters of its SHA-1 hash. If it is found, assume attackers have it and change it on every site where you used it.
What is the most hacked password?
"123456" leads nearly every list of leaked passwords, followed by "password" and "12345678". See our list of the 200 most common passwords to check whether yours, or something like it, is there.
Does adding a symbol make my password strong?
Usually not by much. Swapping a for @ or adding ! at the end are among the first transformations cracking tools try. Length and genuine randomness matter far more than which character classes appear.