About the Password Strength Calculator
Passwords are still the main lock on most online accounts, and weak ones are the most common way accounts are broken into. But judging a password by eye is difficult. A password that looks complicated, such as P@ssw0rd, can be one of the first guesses an attacker tries, while a simple-looking phrase of four random words can be very strong.
This password strength calculator estimates how strong a password is in bits of entropy, how long it would take to crack with an offline attack and an online attack, and whether it uses the common passwords and patterns that attackers try first. It gives a plain rating and advice for making the password stronger. The check runs entirely in your browser: the password is never sent anywhere.
How to Use the Password Strength Calculator
Type or paste a password into the box. The result updates when you press Calculate.
For your own safety, it is good practice to test a password that is similar to the one you use, rather than the real one.
How Password Strength Is Worked Out
character pool = 26 lowercase + 26 uppercase + 10 digits + 33 symbols
(only the kinds the password uses)
entropy (bits) = length × log2(character pool)
average guesses = 2^(entropy − 1)
crack time = average guesses ÷ guesses a second
The calculator also checks for common passwords, including versions with letters swapped for symbols (@ for a, 0 for o, $ for s), a single character repeated, keyboard and number sequences such as qwerty and 1234, and a year at the end. A common password is rated very weak, and any other pattern caps the rating at weak, because attackers try those guesses long before searching every combination.
Step-by-Step Example
kX9#mQ2$vL — 10 characters using all four kinds.
Pool: 26 + 26 + 10 + 33 = 95 characters
Entropy: 10 × log2(95) = 10 × 6.57 = about 66 bits
Guesses: 2^65.7 ÷ 2 = about 3 × 10^19
Offline: at 10 billion guesses a second = about 95 years
P@ssw0rd has 8 characters from the same pool, about 53 bits on paper, but it is a common password with simple swaps, so it is rated very weak.
What the Ratings Mean
| Entropy | Rating |
|---|---|
| Under 28 bits | Very weak |
| 28 – 39 bits | Weak |
| 40 – 59 bits | Reasonable |
| 60 – 79 bits | Strong |
| 80 bits or more | Very strong |
Each extra bit doubles the number of guesses an attacker needs. A password with 80 bits of entropy would take, on average, over a million times as long to crack as one with 60.
Online and Offline Attacks
An online attack tries passwords against a live login page. Most services limit the number of attempts, so an attacker might manage only a few guesses a second or fewer. An offline attack happens when a database of scrambled (hashed) passwords is stolen. The attacker can then try billions of guesses a second on their own equipment, limited only by computing power and how the passwords were stored. Because data breaches are common, a strong password should resist an offline attack.
Why Entropy Is an Upper Bound
The entropy calculation assumes an attacker tries every combination of characters. Real attackers are smarter: they start with lists of leaked passwords, dictionary words, names, dates and common substitutions. A password built from a word and a year, such as summer2024, is far weaker than its entropy suggests. The pattern checks catch the most common cases, but no simple calculator can spot every word or personal detail. The safest passwords are generated randomly or made from several randomly chosen words.
Passphrases
A passphrase of four or more random words, such as those chosen by rolling dice against a word list, is long, easy to remember and hard to guess. What matters is that the words are chosen randomly, not a famous quotation or song lyric. Four words chosen at random from a list of 7,776 give about 52 bits of real entropy; six words give about 78. Adding a separator, a capital letter or a digit adds a little more.
Good Password Habits
Use a different password for every account, so one breach does not unlock the rest.
Use a password manager to generate and remember long random passwords.
Turn on two-factor authentication wherever it is offered.
Change a password if a service you use reports a breach.
How Attackers Really Guess
Password crackers work through guesses in order of likelihood. First come the millions of passwords leaked in past breaches, then dictionary words and names with common changes — capital first letters, numbers and years at the end, symbol swaps — and only then every combination of characters. That is why a password made from a word plus a year falls quickly, however long it is.
Understanding Your Result
Strength gives the overall rating.
Entropy shows the length, the character pool and the bits of entropy.
Offline attack estimates the average time at 10 billion guesses a second.
Online attack estimates the average time at 10 guesses a second.
Patterns lists any common patterns found.
Advice suggests how to strengthen the password.
When Should You Use This Calculator?
Choosing a new password.
Checking whether an old password is still strong enough.
Teaching how password strength works.
Comparing a passphrase with a complex password.
Setting password rules for a team or website.
Common Mistakes
Relying on symbol swaps such as @ for a.
Adding a year or a number at the end of a word.
Reusing the same password on several sites.
Choosing length over randomness with a famous phrase.
Typing a real password into untrusted websites.