Password Strength Meter
Check password strength with entropy-based scoring and crack-time estimates.
Enter a password · 0/100
Checklist
- ✗ At least 12 characters
- ✗ Contains an uppercase letter (A–Z)
- ✗ Contains a lowercase letter (a–z)
- ✗ Contains a digit (0–9)
- ✗ Contains a symbol (!@#$…)
Tips for a strong password
- Longer beats complex: a 16-character passphrase of random words is stronger than an 8-character jumble.
- Never reuse passwords across sites — use a password manager.
- Turn on two-factor authentication wherever it is offered.
Crack times assume 10 billion guesses per second. Nothing you type is sent anywhere.
How strong is your password, really?
Most “strength meters” just count character types and call it a day. This free online password strength meter measures entropy — the real mathematical size of the search space an attacker must explore — and converts it into an estimated crack time, so you understand what your password is actually worth.
How it works
Type a password and the tool counts which character groups it uses: lowercase (26), uppercase (26), digits (10) and symbols (32). Entropy in bits = length × log₂(character set size). A 12-character password using all four groups has about 79 bits of entropy. Crack time assumes an attacker trying 10 billion guesses per second — roughly what a modern GPU rig can do against a fast hash.
Reading the results
The 0–100 score maps to five labels: Very Weak, Weak, Fair, Strong and Excellent. Aim for Strong or better on anything important. The checklist shows exactly which boxes your password fails — length, uppercase, lowercase, digit, symbol — so you know what to fix instead of guessing.
The honest caveats
Entropy assumes random passwords. A 20-character dictionary phrase like “my dog likes to run fast” has high nominal entropy but falls quickly to dictionary attacks. Use a password manager to generate and store truly random passwords, and enable two-factor authentication on important accounts. Your test password is analyzed locally in your browser and never transmitted — but as a rule, never paste a real password into any website.