Password Strength Checker
Estimate guess difficulty with zxcvbn dictionaries and pattern matching instead of only counting character categories. The report shows a 0–4 score, character count, logarithmic guess estimate and pattern categories. These are model estimates, not a breach lookup or a check of an account’s actual security.
Key features
- Common words, repeats, sequences and keyboard-pattern matching
- A 0–4 score and logarithmic guess estimate
- Masked input by default with a user-controlled visibility toggle
- Copyable aggregate JSON without the original or matched words
How to use
- Enter a string to check. It is masked by default.
- Press Run to load the model and analyze its patterns.
- Review the score, character count, guess estimate and pattern categories together.
- Use Reset when finished. If needed, copy only the aggregate report, which excludes the original text.
Use cases
- Compare whether simple substitutions hide a common word
- Explore the estimate difference between repetition and a long random phrase
- Prepare password education examples without including the input in the report
Frequently asked questions
Does a score of 4 guarantee security?
No. The score is a pattern-based estimate. It does not account for reuse, breaches, phishing, server storage or multi-factor authentication. It cannot guarantee an account’s actual security.
Does this check a breached-password database?
No. It calls no breach or account lookup API. breachLookupPerformed is false; that does not mean the password has never been exposed.
Are the input or matched words stored?
The tool does not write input or matches to storage, logs or analytics events. It creates a model instance for each check and keeps only the aggregate report. Input remains in the current page state until reset or navigation. Immediate complete erasure from JavaScript memory cannot be guaranteed.
Does it assess Korean words accurately?
Korean input is accepted, but the model uses common patterns and English dictionaries. It may miss Korean words or personal context, so do not treat the score as an absolute measure.
What does the power-of-ten number mean?
The exponent is the base-10 logarithm of the model’s estimated guesses. Real attack time depends on the attack method and server rate limits, so this tool does not present a definitive cracking time.
Why can the length limit differ from the displayed count?
Input is limited to 128 UTF-16 code units. The report counts Unicode code points, so some emoji use two units for the input limit. Combining characters may also make this differ from the number of visible characters.
Privacy
Checks run in your current browser. Input, matched words and results are not sent to a server or written to browser storage or analytics events. The copyable report contains only aggregate scores and pattern categories, never the original text.
Comments & questions