Sign up free

Password Strength Checker

Type a password to see how guessable it is, how long it could take to crack and how to improve it.

About Password Strength Checker

A password strength checker should tell you more than a green bar. Type a password and you see its length, which character types it uses and its estimated entropy in bits. The checker also looks for the patterns attackers try first: common passwords, keyboard runs such as qwerty or 1qaz, repeated characters, sequences like abc or 123, years and dates, and leetspeak swaps like p@ssw0rd.

From that it estimates how long cracking would take in an online attack, where a login page limits the guesses, and in an offline attack on a stolen password database, where billions of guesses a second are possible. Each weakness comes with a specific suggestion. The password is checked only in your browser and is never sent anywhere. To make a strong one from scratch, use the Password Generator.

How to use Password Strength Checker

  1. 1
    Type the password

    It's checked in your browser and never sent anywhere.

  2. 2
    Read the analysis

    See length, character types, entropy and any patterns found.

  3. 3
    Check the crack time

    Compare the estimates for online and offline attacks.

  4. 4
    Follow the suggestions

    Fix what's flagged, or generate a new random password.

Why use Cubfile for this

  • Pattern detection

    Common passwords, keyboard runs, repeats, sequences, dates and leetspeak.

  • Two crack-time estimates

    Separate figures for online guessing and offline cracking.

  • Specific advice

    Suggestions that point at the exact weakness.

  • Never sent

    Everything happens in your browser, even offline.

FAQ

Password Strength Checker: questions and answers

Is it safe to type my real password here?
The check runs entirely in your browser, and nothing is sent or stored. If you'd rather be careful, test a password with the same structure instead of the real one.
Why is P@ssw0rd rated weak?
Swapping letters for look-alike symbols is one of the first tricks cracking tools try, so it adds very little. The checker recognizes this leetspeak and flags it.
What is password entropy?
A measure in bits of how many guesses a password could take, where each extra bit doubles the work. Patterns lower the real strength, which is why they're checked separately.
What's the difference between online and offline cracking?
Online, an attacker guesses through a login page that can slow them down or lock the account. Offline, they have a stolen hash database and can try billions of guesses a second, so only long, random passwords hold up. To see what a password looks like as an MD5 or SHA-256 hash, try the Hash Generator.
How long should a password be?
At least 16 characters for accounts that matter. Length counts for more than symbols, and a random password kept in a password manager is best.
Share Password Strength Checker with a friendIt runs in any browser, and they can try it without signing up.

Related tools

TXT Password GeneratorMake strong random passwords on your device.
HASH Hash GeneratorGet MD5, SHA-1, SHA-256, SHA-512 and SM3 hashes of text in one go.
TIME Unix Timestamp ConverterConvert Unix timestamps to dates and back, in your time zone and UTC.
U+UNI Unicode ConverterConvert text to and from \u escapes, &#; codes, U+ points and UTF-8 bytes.
AES AES Encrypt and DecryptEncrypt or decrypt text with AES in GCM, CBC or CTR mode.
&;HTML HTML Entity Encoder/DecoderEscape text into HTML entities, or turn entities back into text.
JWT JWT DecoderDecode a JSON Web Token’s header and payload and check its expiry and signature.
01BIN Number Base ConverterConvert numbers between binary, octal, decimal, hex and any base up to 36.