How strong is your password?
Type or paste a password to see entropy, estimated crack time, and whether it hits a common leaked-password list. Everything runs in this tab. The password is never uploaded. This is a local strength check—not a Have I Been Pwned lookup.
Updates as you type, with a grade in about 0.3 seconds. Nothing is written to local storage or sent to the server.
Loading the weak-password list…
Nothing to score yet. After you type, you will see Weak / Medium / Strong / Very strong, plus whether it hits the public leaked-password list.
Offline brute force about
—
Grade —
Risk flags
Suggestions
Do not keep using a weak password. Create a new one locally in the Password Generator.
What this checker covers — and what it does not
Entropy, weak patterns, and list matching all finish in the current tab. The password is not put in an HTTP request and is not written to analytics.
Before you test a password
No. Entropy estimates, weak-pattern checks, and list matching all finish in the current tab. The password is not sent as an HTTP request and is not written to analytics. After you close the page, the server has no copy of this input.
After the audit
Replace a weak password. Generation, one-time sharing, and file backup all stay in the browser. Plaintext, keys, and files are not uploaded by default.