Password Strength Checker
Check password strength safely: the test runs on your device and nothing is sent anywhere.
- Runs on your device
- No watermark
- Free, no signup needed
- Available offline
Make a list
Generated on your device with crypto.getRandomValues. Nothing is sent or stored. Passphrases use the EFF long word list (7,776 words).
A username that does not contain your name, birth year or town keeps your accounts harder to link and your security answers harder to guess.
Make a list
Made on your device from a hand-picked list of friendly words. Nothing is sent, so names are not checked against existing accounts.
Has this password appeared in a data breach?
Optional, and only when you press the button. Your password never leaves this device: it is turned into a SHA-1 fingerprint here and only the first 5 of its 40 characters are sent to Have I Been Pwned. The list of matching fingerprints comes back and is compared on your device.
Strength
How to use it
- Type a password.
- See its score, estimated crack time and warnings.
- Optionally check it against known breaches, then follow the suggestions.
Questions
Is it safe to type my real password?
The strength check runs in your browser and nothing is transmitted. The breach check is optional and sends only 5 characters of a fingerprint, never the password. Even so, security experts recommend testing a similar password rather than one you use.
How is strength measured?
With zxcvbn, the open-source estimator created at Dropbox. It looks for dictionary words, names, dates, keyboard patterns and common substitutions, not just length.
What makes a password strong?
Length and unpredictability. Several random words, or 16 or more random characters, beat a short word with symbols swapped in (like P@ssw0rd), which crackers try early.
Does my password get sent to Have I Been Pwned?
No. Your browser turns the password into a SHA-1 fingerprint on your device and sends only the first 5 of its 40 characters to the Pwned Passwords service. Hundreds of unrelated fingerprints share those 5 characters; the list comes back with extra padding entries, and the match is checked on your device. This is the k-anonymity method published by Have I Been Pwned. Nothing is sent until you press the button.
Keep exploring In-Right
Independent reviews and buying guides for the gear behind the task.



