Password Strength Checker

Breach check is opt-inSecurity

See how quickly a password could be guessed, what makes it weak, and whether it appears in data breaches.

Checked on this device as you type. Nothing is sent or saved.

StrengthNot checked
Online attack–a login page that limits attempts (100 guesses an hour)
Offline attack–a leaked database with a fast hash (10 billion guesses a second)

Optional. Only the first 5 characters of the password's SHA-1 hash are sent to api.pwnedpasswords.com (Have I Been Pwned), never the password itself.

How to use, limits & privacy

About Password Strength Checker

Check how easy your password is to guess. Instead of only counting upper case letters, digits and symbols, it looks for what attackers actually try first: the most common passwords, Indian names, cities and cricket words, look-alike swaps such as @ for a, keyboard patterns, sequences, years and dates. You get a 0 to 4 rating, crack times for an online and an offline attack, and specific advice. It runs in your browser.

How to Use

1

Type the password

Type or paste it into Password. It is checked as you type; use the eye button to show or hide it, or Try an example to see how it works.

2

Read the result

See the rating from Very weak to Very strong, the estimated time for an online and an offline attack, and the list of patterns that make it easier to guess.

3

Optionally check breaches

Click Check if this password appears in data breaches to search the Have I Been Pwned list. Only a 5-character piece of the password's hash is sent.

4

Fix it

Follow How to make it stronger, or use Generate a strong password to create a random password or passphrase.

Privacy & Processing

  • Mode: hybrid
  • Files Leave Browser: Selected data may be sent to a service or peer
  • Max Input Size: API dependent
  • Account Required: No
  • Data Stored Locally: Nothing is saved; the password is cleared when you leave or reload the page.
  • Network Processing: Required for connected features

Passwords are checked in your browser. Only if you click the breach check, the first 5 characters of the password's SHA-1 hash are sent to api.pwnedpasswords.com (Have I Been Pwned). The common-password list comes from SecLists (MIT licence).

Rules & Limitations

  • The result is an estimate. A password nobody has used can still be weak if it follows a pattern this checker does not know.
  • The offline time assumes 10 billion guesses a second against a fast hash such as MD5 or SHA-1. Sites that store passwords with bcrypt or Argon2 are much slower to attack.
  • The online time assumes a login page that allows about 100 attempts an hour.
  • The breach check runs only when you click it and needs an internet connection.

Top Suggestions

  • Checking a new password for email, bank, UPI or college portal accounts
  • Seeing why Name@123 style passwords are weak
  • Finding out whether a password has appeared in a data breach
  • Teaching students and staff what makes a password strong

Password Strength Checker FAQ

How do I check if my password is strong?

Type it into the box. A rating of Strong or Very strong with an offline crack time of days or more is good. Very weak and Weak passwords would be guessed in seconds once a site's database leaks.

Why is India@123 a weak password?

It is one of the most common passwords in India: a well-known word with a capital letter, then @ and 123. Attackers try exactly this shape first, so ticking the boxes for capital, symbol and number does not make it strong.

What makes a password weak?

Names (Rahul, Priya, Krishna), places (Mumbai, Delhi, India), cricket words (Sachin, Dhoni, Kohli18), years and birthdays (1995, 15081990), keyboard patterns (qwerty, 1qaz2wsx) and sequences (abcd, 123456). Swapping letters for symbols, as in P@ssw0rd, does not help because attackers try those swaps too.

Is it safe to type my real password here?

The check runs entirely in your browser and nothing is sent or saved. The optional breach check sends only the first 5 characters of the password's SHA-1 hash to api.pwnedpasswords.com, never the password. If you prefer, test a password that is similar but not the same.

How does the data breach check work?

It uses Have I Been Pwned's range search. Your browser hashes the password with SHA-1, sends the first 5 characters, and receives every breached hash that starts with them; the match is found on your device. If the password is listed, stop using it everywhere.

How long should a password be?

At least 12 random characters, or 4 to 6 random words. Length helps far more than adding a symbol. Use a different password for every account and a password manager to remember them.