Skip to content
Popular Calculators
Browse Other calculators

Password Strength Calculator

Check how strong a password is: its entropy in bits, how long a brute-force attack would take, and whether it uses common patterns attackers try first.

Checked in your browser and never sent anywhere.

About the Password Strength Calculator

Passwords are still the main lock on most online accounts, and weak ones are the most common way accounts are broken into. But judging a password by eye is difficult. A password that looks complicated, such as P@ssw0rd, can be one of the first guesses an attacker tries, while a simple-looking phrase of four random words can be very strong.

This password strength calculator estimates how strong a password is in bits of entropy, how long it would take to crack with an offline attack and an online attack, and whether it uses the common passwords and patterns that attackers try first. It gives a plain rating and advice for making the password stronger. The check runs entirely in your browser: the password is never sent anywhere.

How to Use the Password Strength Calculator

Type or paste a password into the box. The result updates when you press Calculate.

For your own safety, it is good practice to test a password that is similar to the one you use, rather than the real one.

How Password Strength Is Worked Out

  character pool   =  26 lowercase + 26 uppercase + 10 digits + 33 symbols
                      (only the kinds the password uses)
  entropy (bits)   =  length × log2(character pool)
  average guesses  =  2^(entropy − 1)
  crack time       =  average guesses ÷ guesses a second

The calculator also checks for common passwords, including versions with letters swapped for symbols (@ for a, 0 for o, $ for s), a single character repeated, keyboard and number sequences such as qwerty and 1234, and a year at the end. A common password is rated very weak, and any other pattern caps the rating at weak, because attackers try those guesses long before searching every combination.

Step-by-Step Example

kX9#mQ2$vL — 10 characters using all four kinds.

  Pool:       26 + 26 + 10 + 33              =  95 characters
  Entropy:    10 × log2(95)                  =  10 × 6.57  =  about 66 bits
  Guesses:    2^65.7 ÷ 2                     =  about 3 × 10^19
  Offline:    at 10 billion guesses a second  =  about 95 years

P@ssw0rd has 8 characters from the same pool, about 53 bits on paper, but it is a common password with simple swaps, so it is rated very weak.

What the Ratings Mean

EntropyRating
Under 28 bitsVery weak
28 – 39 bitsWeak
40 – 59 bitsReasonable
60 – 79 bitsStrong
80 bits or moreVery strong

Each extra bit doubles the number of guesses an attacker needs. A password with 80 bits of entropy would take, on average, over a million times as long to crack as one with 60.

Online and Offline Attacks

An online attack tries passwords against a live login page. Most services limit the number of attempts, so an attacker might manage only a few guesses a second or fewer. An offline attack happens when a database of scrambled (hashed) passwords is stolen. The attacker can then try billions of guesses a second on their own equipment, limited only by computing power and how the passwords were stored. Because data breaches are common, a strong password should resist an offline attack.

Why Entropy Is an Upper Bound

The entropy calculation assumes an attacker tries every combination of characters. Real attackers are smarter: they start with lists of leaked passwords, dictionary words, names, dates and common substitutions. A password built from a word and a year, such as summer2024, is far weaker than its entropy suggests. The pattern checks catch the most common cases, but no simple calculator can spot every word or personal detail. The safest passwords are generated randomly or made from several randomly chosen words.

Passphrases

A passphrase of four or more random words, such as those chosen by rolling dice against a word list, is long, easy to remember and hard to guess. What matters is that the words are chosen randomly, not a famous quotation or song lyric. Four words chosen at random from a list of 7,776 give about 52 bits of real entropy; six words give about 78. Adding a separator, a capital letter or a digit adds a little more.

Good Password Habits

Use a different password for every account, so one breach does not unlock the rest.

Use a password manager to generate and remember long random passwords.

Turn on two-factor authentication wherever it is offered.

Change a password if a service you use reports a breach.

How Attackers Really Guess

Password crackers work through guesses in order of likelihood. First come the millions of passwords leaked in past breaches, then dictionary words and names with common changes — capital first letters, numbers and years at the end, symbol swaps — and only then every combination of characters. That is why a password made from a word plus a year falls quickly, however long it is.

Understanding Your Result

Strength gives the overall rating.

Entropy shows the length, the character pool and the bits of entropy.

Offline attack estimates the average time at 10 billion guesses a second.

Online attack estimates the average time at 10 guesses a second.

Patterns lists any common patterns found.

Advice suggests how to strengthen the password.

When Should You Use This Calculator?

Choosing a new password.

Checking whether an old password is still strong enough.

Teaching how password strength works.

Comparing a passphrase with a complex password.

Setting password rules for a team or website.

Common Mistakes

Relying on symbol swaps such as @ for a.

Adding a year or a number at the end of a word.

Reusing the same password on several sites.

Choosing length over randomness with a famous phrase.

Typing a real password into untrusted websites.

Frequently Asked Questions

How is password strength measured?

By entropy, in bits: the length multiplied by log2 of the number of possible characters. A 10-character password using lowercase, uppercase, digits and symbols, a pool of 95, has about 66 bits, which is strong against brute force.

How long would it take to crack my password?

It depends on the attack. At 10 billion guesses a second, an offline attack on a 66-bit password takes on average about 95 years. A common password or a simple pattern falls almost instantly, whatever its length.

Why is P@ssw0rd rated very weak?

Because attackers try common passwords first, including versions with letters swapped for symbols such as @ for a and 0 for o. Its 8 characters look varied, but the pattern is one of the first guesses in any attack.

Is a long passphrase better than a complex password?

Usually. Four or more random words are long, easy to remember and hard to guess. What matters is that the words are chosen randomly, not a famous phrase or song lyric, and that the passphrase is not reused.

Is it safe to type my password here?

The check runs entirely in your browser; the password is not sent to any server or stored. Even so, it is good practice to test a similar password rather than one you actually use.

What makes a password strong?

Length above all: at least 12 characters, more for important accounts. Mix character types, avoid words, names, dates and patterns, and use a different password for every account, which a password manager makes easy.

Last reviewed September 28, 2026 by the CalculatorPeak editorial team.