All tools

Password Strength Checker

Check password strength safely: the test runs on your device and nothing is sent anywhere.

  • Runs on your device
  • No watermark
  • Free, no signup needed
  • Available offline

Has this password appeared in a data breach?

Optional, and only when you press the button. Your password never leaves this device: it is turned into a SHA-1 fingerprint here and only the first 5 of its 40 characters are sent to Have I Been Pwned. The list of matching fingerprints comes back and is compared on your device.

Strength

How to use it

  1. Type a password.
  2. See its score, estimated crack time and warnings.
  3. Optionally check it against known breaches, then follow the suggestions.

Questions

Is it safe to type my real password?

The strength check runs in your browser and nothing is transmitted. The breach check is optional and sends only 5 characters of a fingerprint, never the password. Even so, security experts recommend testing a similar password rather than one you use.

How is strength measured?

With zxcvbn, the open-source estimator created at Dropbox. It looks for dictionary words, names, dates, keyboard patterns and common substitutions, not just length.

What makes a password strong?

Length and unpredictability. Several random words, or 16 or more random characters, beat a short word with symbols swapped in (like P@ssw0rd), which crackers try early.

Does my password get sent to Have I Been Pwned?

No. Your browser turns the password into a SHA-1 fingerprint on your device and sends only the first 5 of its 40 characters to the Pwned Passwords service. Hundreds of unrelated fingerprints share those 5 characters; the list comes back with extra padding entries, and the match is checked on your device. This is the k-anonymity method published by Have I Been Pwned. Nothing is sent until you press the button.

Keep exploring In-Right

Independent reviews and buying guides for the gear behind the task.

More free tools

All tools

move open closeAll tools