Password Entropy Meter
A real strength check based on actual randomness — not just whether you remembered to add a capital letter and a number.
Check your password strength
How to use this tool
-
1
Type a password. Nothing is sent anywhere — the check happens live as you type, entirely on your device.
-
2
Read the entropy score. Higher bits means more genuine randomness — the actual measure of how hard a password is to guess.
-
3
Check the flagged issues. If something specific is weakening your password — a common pattern, repetition, a keyboard sequence — it's called out directly.
About This Tool
Most password strength meters just check boxes: is there a capital letter, a number, a symbol? That approach is easy to game — "Password1!" passes every box and is still one of the first passwords an attacker tries. Real strength comes from entropy: how much genuine randomness and unpredictability the password actually contains.
This tool estimates entropy properly — it rewards length (a long, simple passphrase can beat a short, "complex" one), and it specifically checks for and penalizes the patterns that make passwords easy to guess despite looking complicated: known common passwords, keyboard-adjacent sequences like "qwerty," sequential runs like "abc123," and repeated characters.
Frequently Asked Questions
Is my password sent anywhere or stored?
No. This runs entirely in your browser using JavaScript. Nothing is transmitted, logged, or saved — not even locally. It disappears the moment you close or refresh the tab.
What does the crack time estimate actually mean?
It's a rough estimate assuming an attacker can try 10 billion guesses per second — a realistic rate for a fast offline attack against a leaked password database. Real-world numbers vary a lot depending on how the password was stored and what hardware is used.
Is this as thorough as tools like zxcvbn?
No — this is a lighter-weight heuristic check, not a full dictionary-backed analyzer. It catches common passwords, keyboard patterns, repetition, and sequences, but it won't catch every possible dictionary word or clever letter-substitution trick (like "p@ssw0rd").
Why did a "strong-looking" password score lower than expected?
Character variety alone doesn't guarantee strength. A short password with a capital letter, number, and symbol can still score lower than a long, plain phrase — length and true unpredictability matter more than checkbox complexity.