Type or paste
01Masked by default. Updates as you type; the rating appears in about 0.3 seconds. The password is not written to local storage and is not sent to the server.
Open and use it—no signup. After you type or paste, this tab runs a password strength test: it estimates entropy and crack time, then checks a public leaked weak-password list shipped with the page. The password is not uploaded and is not written to analytics. This page can catch common weak passwords, but it cannot prove a string never appeared in any dump.
Masked by default. Not written to local storage, and not sent to the server.
Loading the weak-password list…
Nothing to rate yet. After you type, you will see Weak / Medium / Strong / Very strong, and whether it hits the public leaked weak-password list.
Offline brute force ~
—
Rating —
Do not keep using a weak password. Draw a new one locally in the password generator.
Masked by default. Updates as you type; the rating appears in about 0.3 seconds. The password is not written to local storage and is not sent to the server.
The page shows Weak / Medium / Strong / Very strong, plus offline brute-force and online rate-limited time scales. A hit on the public weak-password list is forced to Weak.
Draw a new password locally in the online password generator. Do not reuse the old one on important accounts. This page is not a full-web leak lookup.
Bits are estimated from length and character classes, with offline brute-force and online rate-limited time scales. Shorter than 8 characters, too few classes, or keyboard sequences pull the rating down. Progress bar colors: Weak is red, Medium orange, Strong cyan, Very strong green.
The list downloads with the page, then is searched in four steps: exact match, case fold, strip a trailing 0–999, and common Leet. A hit is marked Weak with a very high-risk warning. Strings longer than 128 characters get exact and case-fold matching only.
It can catch passwords that are already widely abused. It cannot prove a password never appeared in any breach. This page does not query Have I Been Pwned and does not send the password to an external API.
The password strength checker only answers “does this string look strong right now.” Thresholds, list scope, and what it cannot do are written on this page.
Entropy, weak patterns, and the list check all run in the browser. The password does not enter an HTTP request and is not written to analytics. After you close the tab, this device does not keep that input.
Estimated entropy ≥ 80 bits is Very strong, ≥ 60 Strong, ≥ 40 Medium, otherwise Weak. Shorter than 8 characters, a common weak password, or a public-list hit is forced to Weak.
It checks a built-in public high-frequency leaked-password list, not a full-web dump set. Strings longer than 128 characters skip trailing-digit and Leet variants.
No signup. This site has no password vault and does not keep audit history. After you refresh, plaintext you did not save yourself does not appear on any remote system.
If it is too weak, draw a new one. Generate, share once, and back up a file without leaving the browser. Plaintext, keys, and files are not uploaded by default.