Password Strength Checker
Free password checker. Type a password to test its strength, see how strong it is, how long it would take to crack, and how to make it stronger.
Start typing
- At least 12 characters
- Lowercase letter
- Uppercase letter
- Number
- Symbol
- Not a common pattern
Has this password appeared in a data breach?
Optional. Uses the Have I Been Pwned k-anonymity API: only the first 5 characters of your password’s SHA-1 hash are sent. Your password itself never leaves this page.
Tip: don’t test the exact password you use for your bank or email. Test one built the same way.
How the password checker works
The checker estimates how many guesses an attacker would need to crack your password. It uses zxcvbn, an open-source strength estimator originally built by Dropbox, which spots common passwords, names, dictionary words, keyboard patterns like qwerty, dates and l33t-speak substitutions. A long password made of a common word plus 123! scores low, even though it ticks every box.
All of this runs inside your browser. Your password is never sent to Cyber Strike News or anyone else.
What the crack times mean
- Online attack (rate-limited): someone guessing through a login page that limits attempts to about 100 per hour.
- Offline attack (fast hash): an attacker who has stolen a database of weakly hashed passwords and tests 10 billion guesses per second on GPUs. This is the case that matters after a data breach.
How to make a strong password
- Length first. Use at least 12 characters; 16 or more is better.
- Use a passphrase. Four or more random, unrelated words (for example orbit-velvet-cactus-lantern) are long, strong and easy to type.
- Never reuse passwords. When one site is breached, attackers try the same password everywhere else.
- Use a password manager to create and store a unique password for every account.
- Turn on multi-factor authentication so a stolen password alone is not enough.
Password strength levels
| Score | Rating | Estimated guesses needed |
|---|---|---|
| 0 | Very weak | Under 1,000 |
| 1 | Weak | Under 1 million |
| 2 | Fair | Under 100 million |
| 3 | Strong | Under 10 billion |
| 4 | Very strong | 10 billion or more |
Related free tools
- Subnet Calculator (IPv4) – network, broadcast, host range and subnet masks
- IPv6 Subnet Calculator – IPv6 network range, /64 count and reverse DNS zone
- All free cybersecurity tools – every tool in one place
Stay current on the threats these tools help defend against: read the latest vulnerability news, threats and malware and data breach coverage on Cyber Strike News.
Frequently asked questions
Is it safe to type my password into this checker?
Yes. The strength check runs entirely in your browser and your password is never sent or stored. As a precaution, you can test a password built the same way rather than your real one.
How does the data breach check work?
It uses the Have I Been Pwned Pwned Passwords API with k-anonymity. Only the first 5 characters of your password’s SHA-1 hash are sent, and the match is done in your browser.
How long should a password be?
At least 12 characters, and 16 or more for important accounts. Length adds more strength than swapping letters for symbols.
Is a passphrase better than a complex password?
Usually, yes. Four or more random words give a long password that is hard to crack and easy to remember.
Why does my password with symbols still score weak?
Attackers’ tools know common substitutions like P@ssw0rd and patterns like Word123!. The checker detects these, so they score low despite meeting complexity rules.
What does crack time mean?
It is an estimate of how long an attacker would need to guess the password, either online through a rate-limited login or offline after stealing a hashed password database.
