Password Strength Analyser

See instantly how resilient a password is: character variety, entropy (unpredictability in bits), and the estimated time a hypothetical attacker would need to crack it.

Runs 100% in your browser — the password you type is never sent anywhere, never transmitted to a server, and never saved to localStorage; it only stays in your device's memory while this page is open, and disappears when you close the tab.
lowercase (a-z) UPPERCASE (A-Z) digit (0-9) symbol (!@#$…)
Type a password above to analyse it…
Entropy
—
Estimated crack time
—
The crack time is a rough estimate based on the assumption of a determined offline attacker capable of 10 billion guesses per second — the real time can vary hugely depending on how the password is stored (e.g. slow algorithms like bcrypt/Argon2 increase it dramatically).

What Is Entropy, and What Makes a Password Strong?

Contrary to intuition, a password's strength isn't measured by how complex it looks, but by how many different possible combinations it could have been drawn from. This measure is called entropy, and it's computed roughly as length × log2(character pool size) — expressed in bits. Every extra bit doubles the number of possible combinations; so as both the password's length and the variety of character types used (lowercase/uppercase, digits, symbols) increase, guessing it at random becomes exponentially harder.

Length matters more than complexity: an 8-character password made only of lowercase letters has 26⁸ (~208 billion) possible combinations, while going to 16 characters with the same character pool raises that number to 26¹⁶ (~4×10²²) — a gain of billions of times. Adding symbols and uppercase letters helps too, but a few extra characters usually gain you more.

The "estimated crack time" on this tool is meant only to give you a sense of scale, based on one assumption: a determined attacker capable of 10 billion guesses per second against a stolen password database (hashed or not). In the real world this time can range from seconds to centuries depending on how the target system stores passwords — so the number shown here isn't a guarantee, it's a relative comparison tool.

Practical tip: generating a separate, random password for every account and storing it in a password manager (1Password, Bitwarden, etc.) solves length, variety, and "reusing the same password" risk all at once. You can also try our own generator — Password Generator.

Try This Next

Finished here? These might be your next step.

Frequently Asked Questions

Entropy is a measure, in bits, of how "unpredictable" a password is, computed roughly as length × log2(character pool size). Every extra bit doubles the number of possible combinations; so as both length and the variety of character types used (lowercase/uppercase, digits, symbols) increase, brute-forcing the password becomes exponentially harder. The score and "crack time" estimate on this tool are based on exactly this calculation.

No, absolutely not. The analysis happens entirely in this page's JavaScript, in your browser's memory; your password is never sent to a server, no network request (fetch/XHR) is triggered, it's never written to localStorage/sessionStorage, and it's never sent to analytics tools. If you close the tab or refresh the page, the password you typed is permanently lost.

The calculation divides your password's number of possible combinations (2entropy) by a fixed guess rate (10 billion guesses per second in this tool — a determined attacker scenario using GPUs/ASICs against a stolen hash database). This is a rough estimate, not a guarantee: the real time can range from seconds to thousands of times longer depending on whether the target system stores passwords in plain text or with a deliberately slow algorithm like bcrypt/scrypt/Argon2. The goal isn't an exact number but letting you compare different passwords relative to each other.

In general, length wins. Every extra character multiplies the number of combinations by the size of the character pool (e.g. 26 or 90 times) — so adding a few more characters usually gains far more entropy than adding a symbol or uppercase letter. Doing both (long AND varied character types) is ideal for the strongest result, but if you have to pick one, increasing length is more effective.

If you're getting a "Weak" or "Medium" result — especially for a critical account (email, banking) — it's a good idea to strengthen the password. The most practical solution is to stop relying on human memory and use a password manager (1Password, Bitwarden, etc.) to generate and store a separate, long, random password for every account — this eliminates both low entropy and password-reuse risk. Enabling two-factor authentication (2FA) wherever possible is also recommended.

Last updated: