Password Strength Checker – Entropy & Brute-Force Time Estimation

Security Assessment / Entropy Calculation / Crack-time Estimation / Risk Score

Strength:No password (0/100)

Suggestions

  • Enter a password to check its strength

How the Password Strength Checker Works

This tool evaluates password security across several dimensions: it checks length (separate tiers for ≥8 / ≥12 / ≥16 characters), the mix of character types (lowercase, uppercase, digits, symbols), and whether it contains repeated or sequential characters (e.g. aaa, 123). It computes the password’s entropy (the key indicator of randomness, measured in bits) and estimates the time required for a brute-force attack. All computation runs locally in your browser — your password is never uploaded to a server. To generate a strong random password, use the Password Generator.

Password Security Best Practices

Drawing on security standards such as NIST SP 800-63B, the core principles of password security are:

  • Length first: a length of ≥12 characters matters more than a complex mix. Prefer long passphrases or random word combinations.
  • Avoid common patterns: do not use keyboard sequences (qwerty), runs of digits (123456), or personal information (birthdays, names) that are easy to guess.
  • Use a unique password per site: reusing one password everywhere exposes you to credential-stuffing attacks. Use a password manager (e.g. 1Password, Bitwarden) to generate and store passwords.
  • Review regularly: run this tool periodically on your existing passwords and replace any that are weak.

Frequently Asked Questions

How long should a secure password be?

NIST recommends a minimum of 8 characters, and 12 or more is preferred. Longer is safer: an 8-character all-lowercase password has roughly 38 bits of entropy (trivially crackable), while a 16-character mix of upper/lowercase, digits and symbols is roughly 100 bits (extremely hard to crack).

What is entropy, and how many bits are considered safe?

Entropy measures a password’s randomness and is computed as length × log₂(character-set size). Below 40 bits is weak, 40–60 bits is medium, 60–80 bits is strong, and above 80 bits is very strong. This tool integrates length, character-type mix, and common patterns into a 0–100 security score.

Is the brute-force time estimate accurate?

The tool assumes an attack speed of 10 billion guesses per second (reflecting high-performance hardware clusters). Real security also depends on the server’s hash algorithm (bcrypt/scrypt/Argon2 are millions of times slower than MD5), login rate limiting, and salting. Factor these in for a more complete risk assessment.

Does a high password strength guarantee safety?

No. Even a very strong password cannot defend against phishing (tricking you into typing it), keyloggers (capturing your keystrokes), or database breaches (plaintext or weakly hashed storage). Strength is only the first line of defense — you should also enable two-factor authentication (2FA).