Tool · Local analysis
How long would your password hold?
Type a password and get an estimate of its strength, the patterns that weaken it, and the time it would take to break by brute force.
It never leaves your browser

Works locally offline. We save nothing.
Waiting for password...
Estimated for an offline attack at 100B guesses per second (high-end GPU against a fast hash).
What it is actually measuring
The checker does not count characters. It estimates how many attempts an attacker would need to land on your password, working from the most likely candidates to the least — which is how real cracking software behaves.
To do that it looks at four things at once:
- Length and alphabet. How many slots there are, and how many different symbols could fill each one.
- Known words. Dictionary terms, proper nouns and common passwords.
- Typical substitutions. Swapping
afor4orefor3has fooled nobody for thirty years. - Keyboard patterns and sequences.
qwerty,123456,abcdefand their variants.
That is why a password like Passw0rd! scores badly despite having an uppercase letter, a number and a symbol: it sits at the intersection of nearly every rule an attacker tries first.
How to read the result
The estimated time is the eye-catching part and the one that needs the most care. It depends on something you do not control: how the service where you use it stores its passwords.
If that service uses a modern, deliberately slow algorithm, an attacker holding the stolen database can only try a few thousand combinations per second. If it uses something old and fast, they can try billions. Between those two scenarios there are six orders of magnitude.
The practical reading: treat the result as a traffic light, not a stopwatch. Red or amber means change it. Green means reasonable — and the important question is still a different one.
The question this checker cannot answer
Do you use that password on more than one site?
That is what decides most stolen accounts, and no tool that looks at a password in isolation can know it. A perfectly random twenty-character key becomes worthless the moment it leaks from any one of the places you reused it, because from then on it gets tried automatically everywhere else.
So the correct order is: unique first, strong second. If you had to choose between one excellent password reused across ten sites and ten decent passwords that are all different, the second option wins without argument.
What to do about a bad score
- Generate a new one in the generator, or a long phrase in passphrases if you have to memorise it.
- Store it in a password manager instead of trying to remember it.
- Change it first where it hurts most: email, banking and anything holding money.
- Turn on two-factor authentication, which turns a stolen password into a minor problem.
Frequently asked
Common questions
Is it safe to type my real password here?
The calculation happens entirely inside your browser; the password is never sent to a server and nothing is stored once you close the page. Even so, the prudent habit is to test a close variant rather than the exact key you use every day.
Where does the estimated cracking time come from?
From combining the entropy of the password with a reference speed for an offline attack. It is indicative: the real figure depends on how each service stores its passwords, and that cannot be known from the outside.
My password scores as strong. Am I done?
Not necessarily. The checker measures how hard it is to guess, not whether it is unique or whether it has already leaked. An excellent password that appears in a breach is worth nothing, so run it through the breach checker as well.
Why does it penalise words that look random?
Because attackers do not guess at random. They try dictionaries, proper nouns, keyboard patterns and the usual letter-for-number swaps first. A password containing those patterns falls far sooner than its length suggests.
Where to go next