Password Strength Audit
Score passwords and spot weaknesses.
Type a password to audit it.
About Password Strength Audit
Most passwords fail not because they are short but because they are predictable. A capital letter and an exclamation mark appended to a common word adds almost no protection, because cracking tools try exactly that pattern early. This audit measures what actually matters: how much genuine randomness a password carries, expressed as entropy in bits, and how long a serious offline attack would need against it. Below the score, a list of concrete weaknesses appears when they exist, including dictionary entries, repeated characters, keyboard walks like qwerty, trailing years, and the word-plus-digits-plus-symbol shape that password policies accidentally encourage. The password is checked locally in your browser and never transmitted or stored, so it is safe to test a real credential you are considering retiring.
How to Use Password Strength Audit
Type or paste the password
Enter it in the box at the top. It stays hidden as dots until you press the eye button, so shoulder surfing is not a concern in a shared space.
Read the score and entropy
The panel shows a score from 0 to 4, an entropy estimate in bits, and the length. Roughly speaking, under 28 bits is trivially breakable and above 80 bits is beyond practical attack.
Check the crack time estimate
The guess time assumes a serious offline attacker trying ten billion guesses per second. This is the number that puts abstract bits into perspective: minutes versus centuries.
Fix the listed weaknesses
Any detected pattern appears as a bullet with an explanation. Lengthen the password or replace the predictable parts, and watch the score climb as you edit.
Why Use Password Strength Audit: Common Use Cases
Deciding whether an old password is still safe
Test a credential you have used for years. Many turn out to sit at one or two out of four, which is the push needed to replace them before a breach does it for you.
Setting a policy users can actually follow
Test the shapes your current rules produce. If every compliant password scores poorly, the policy rewards decoration rather than length. Generate compliant alternatives with Password Generator.
Comparing passphrase strategies
Try four random words against a short complex string and see the entropy difference for yourself, then pick the approach you will actually remember.
Teaching security basics
The visible link between patterns, bits, and crack time makes the abstract idea of randomness concrete in a way a lecture rarely does.
Password Strength Audit Specifications
| Input Formats | Password text |
|---|---|
| Output Formats | Score (0 to 4), Entropy in bits, Crack time estimate, Weakness list |
| File Size Limit | No strict limit (dependent on device memory) |
| Processing Engine | 100% Client-side (Runs locally in your browser) |
| Data Retention | Files never leave your device |
| Batch Processing | Single file processing |
Tips for Password Strength Audit
Length beats cleverness. Going from twelve to sixteen random characters multiplies the search space far more than adding a symbol to a twelve character word.
Avoid personal patterns entirely: names, birthdays, and favorite teams appear in attacker wordlists in every language, not just English.
A password manager removes the memory problem. Generate a unique random password per site, then audit the ones you cannot yet move over.
Reuse is the risk the score cannot see. A strong password reused on a breached site is a weak password everywhere, so pair this tool with a manager migration.
Pair it with Password Generator to replace anything that scores below three, and store the result immediately.
Frequently Asked Questions
Is my password sent anywhere?
No. The entire audit runs in your browser. There is no network request after the page loads, which matters because a strength checker that receives your password would itself be a risk.
What does entropy in bits actually mean?
Each bit doubles the number of guesses an attacker must try. A password with 40 bits of entropy sits in a space of about a trillion possibilities, and every four extra bits multiply that space by sixteen.
Why does capitalizing a word barely help?
Because capitalizing the first letter is the most common transformation humans apply, so cracking tools try it within the first handful of guesses per word. The same goes for appending one, two, or even three digits at the end.
How accurate is the crack time estimate?
It assumes a well-funded offline attacker with modern hardware at around ten billion guesses per second. Real attacks against a well-salted hash are slower, but a fast hash or no salt can be faster. Treat the number as an order of magnitude, not a countdown.
Is a four-word passphrase really strong?
When the words are chosen at random from a large list, yes. Randomness does the work, not weirdness. Four uncommon words in a random order carry more entropy than an eight character string of symbols most people can remember.
Does this tool check against breach databases?
No, and it does so deliberately to keep your password off the network. It flags a built-in list of the most common passwords and structural weaknesses, which catches the overwhelming majority of bad choices.