Password Strength Checker
See how quickly a password could be guessed, what makes it weak, and whether it appears in data breaches.
Checked on this device as you type. Nothing is sent or saved.
Optional. Only the first 5 characters of the password's SHA-1 hash are sent to api.pwnedpasswords.com (Have I Been Pwned), never the password itself.
Password Strength Checker FAQ
How do I check if my password is strong?
Type it into the box. A rating of Strong or Very strong with an offline crack time of days or more is good. Very weak and Weak passwords would be guessed in seconds once a site's database leaks.
Why is India@123 a weak password?
It is one of the most common passwords in India: a well-known word with a capital letter, then @ and 123. Attackers try exactly this shape first, so ticking the boxes for capital, symbol and number does not make it strong.
What makes a password weak?
Names (Rahul, Priya, Krishna), places (Mumbai, Delhi, India), cricket words (Sachin, Dhoni, Kohli18), years and birthdays (1995, 15081990), keyboard patterns (qwerty, 1qaz2wsx) and sequences (abcd, 123456). Swapping letters for symbols, as in P@ssw0rd, does not help because attackers try those swaps too.
Is it safe to type my real password here?
The check runs entirely in your browser and nothing is sent or saved. The optional breach check sends only the first 5 characters of the password's SHA-1 hash to api.pwnedpasswords.com, never the password. If you prefer, test a password that is similar but not the same.
How does the data breach check work?
It uses Have I Been Pwned's range search. Your browser hashes the password with SHA-1, sends the first 5 characters, and receives every breached hash that starts with them; the match is found on your device. If the password is listed, stop using it everywhere.
How long should a password be?
At least 12 random characters, or 4 to 6 random words. Length helps far more than adding a symbol. Use a different password for every account and a password manager to remember them.