Skip to content
M2TOOLKIT

Password Strength Checker

Find out how strong a password really is and what makes it weak.

  • Free
  • No sign-up
  • Runs in your browser

Checked entirely on your device. Nothing is sent or saved.

Strength
—
Time to crack — online attack (100 guesses/sec)
—
Time to crack — offline attack (10 billion guesses/sec)
—

Estimates assume an attacker who knows common patterns. Real-world risk also depends on how the site stores passwords.

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us.

How to use the Password Strength Checker

  1. Type a password (it's hidden by default).
  2. Read the strength rating and estimated crack times.
  3. Follow the suggestions to improve it.

What does this tool do?

The checker estimates randomness from length and character variety, then penalises patterns attackers try first: common passwords, keyboard runs like “qwerty”, repeated characters, years and “Word123!” structures.

Crack times are shown for a slow online attack (a site limiting guesses) and a fast offline attack (an attacker with a stolen, weakly hashed password list).

Why use it?

  • Test a password before you use it.
  • Understand why “P@ssw0rd2024!” is weak.
  • Checked entirely on your device.

Examples

“Summer2024!” looks complex but follows a very common pattern and rates very weak. A random 16-character password or a six-word passphrase rates very strong.

Accuracy and limits

  • This is an estimate. Clever substitutions (like 0 for o) aren't fully detected, so a password may be weaker than shown. Don't type passwords you currently use on important accounts into any website.

Privacy

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.

Frequently asked questions

Is it safe to do this in a browser?

Yes, because nothing leaves your device. Everything is generated or checked with your browser's built-in cryptography (the Web Crypto API) — no network requests are made with what you type.

Last reviewed by the M2Toolkit team.

Helpful guides

Other tools people use alongside the password strength checker.