Credentials
Password Strength Checker
Entropy is calculated in your browser — the password is never sent anywhere.
Offline crack time
—
Character pool
0 symbols
Breach exposure
Type a password to check it against known breach databases.
Checked privately: only the first 5 characters of the password's hash are sent. The password itself is never transmitted or stored.
Checks
- At least 12 characters
- Mixed upper and lower case
- Contains numbers
- Contains symbols
- Not a common or breached pattern
- No repeats or keyboard runs
How to improve
- Use a passphrase of 4+ random words to reach 16+ characters.
- Mix uppercase and lowercase letters unpredictably.
- Add digits in the middle rather than at the end.
- Include symbols such as ! @ # $ % ^ & to widen the character pool.
- Avoid dictionary words, names, and leaked passwords.
How the password checker works
1. Type or generate
Enter a password or click Generate for a strong random passphrase.
2. Local entropy analysis
Your browser calculates entropy bits, character pool size and an offline crack-time estimate — nothing is transmitted.
3. Private breach lookup
A k-anonymity hash-prefix query checks Have I Been Pwned's breach database without revealing the password.
Frequently asked questions
Related security tools
Email Breach Checker
See what's coming next: a privacy-first way to check if your email appeared in a breach.
Interactive Security Checklist
Turn strong passwords into a full account-security routine with a 50-point checklist.
AI Phishing Detector
Check a message that asked you to 'verify' or reset your password.
Authoritative references
Ready to lock down every account?
Work through the full 50-point security checklist for devices, accounts and banking.
