Password Strength Analyzer
Analyze password entropy, estimate brute-force resistance, and get improvement suggestions. Nothing ever leaves your browser.
Enter a password or secret to see its strength analysis
This tool runs entirely in your browser. Your password never leaves your device.
Password Strength FAQ
What is password entropy?
Entropy measures the randomness of a password in bits. Higher entropy means more possible combinations an attacker must try. A password with 80+ bits of entropy is considered very strong against offline attacks.
How are crack times calculated?
Crack times are estimated by dividing the total number of possible passwords (2^entropy) by the attacker's guessing speed. We show estimates for four scenarios: throttled online, fast online, offline with slow hashing (bcrypt), and offline with fast hashing (MD5 on GPUs).
What makes a strong password?
Strong passwords are long (16+ characters), use a mix of character types, and avoid common patterns. Passphrases — four or more random words — are both strong and memorable. Avoid dictionary words followed by numbers.
Is my password sent to a server?
No. All analysis happens entirely in your browser using JavaScript. Your password never leaves your device — no network requests are made.
Need to share passwords securely?
Don't paste credentials into chat or email. Use CredenShare to deliver them with end-to-end encryption and automatic expiration.