Password Strength Test
Enter your password below to check its strength against common security standards and receive personalized recommendations for improvement.
Your password is never stored or transmitted to any server.
0 characters
Enter a password
0
Very Weak
Warning!
This appears to be a common password. Common passwords are highly vulnerable to dictionary attacks.
Warning!
This password might have been exposed in a data breach. Consider changing it immediately.
Estimated Time to Crack
Online Attack:
Instantly
Offline Attack:
Instantly
Password Criteria
- Length: At least 12 characters
- Uppercase letters: At least one (A-Z)
- Lowercase letters: At least one (a-z)
- Numbers: At least one (0-9)
- Special characters: At least one (!@#$%^&*...)
- No sequences: Avoids common patterns (123, abc)
- No repetition: Avoids repeating characters (aaa, 111)
- Entropy: High unpredictability
How to improve your password
Suggested strong password alternatives:
OWASP Password Recommendations
- Use a minimum password length of 12 characters
- Include lowercase and uppercase letters, numbers, and special characters
- Check against commonly used or compromised passwords
- Limit the number of failed login attempts
- Implement secure password recovery mechanisms
- Store passwords using strong adaptive hashing functions with salt
NIST SP 800-63B Guidelines
- Minimum of 8 characters (though 12+ is recommended)
- Maximum length of at least 64 characters
- Support all ASCII characters including spaces
- Screen passwords against known compromised passwords
- No password hints or security questions
- No periodic password resets without reason
About Password Strength Test
Test the strength of your password against common security criteria and get advice on how to improve it
Estimate resistance to guessing by examining length, character diversity, common patterns, dictionary matches, and predictable sequences.
Key features
- What it examines Estimate resistance to guessing by examining length, character diversity, common patterns, dictionary matches, and predictable sequences.
- Analysis input Type a candidate password directly into the strength field; use a made-up example rather than a live credential on a shared device.
- Signals and controls Review the score, estimated crack time, detected weaknesses, and suggestions rather than relying on color alone.
- How to use the result The result helps compare candidates and identify obvious weaknesses but does not certify an account or storage system as secure.
How to use Password Strength Test
Follow this workflow to work with password strength safely and accurately.
- Provide a sample or target Type a candidate password directly into the strength field; use a made-up example rather than a live credential on a shared device.
- Choose the relevant checks Review the score, estimated crack time, detected weaknesses, and suggestions rather than relying on color alone.
- Run the analysis Run the analysis on the password strength and distinguish direct observations from estimates or heuristic classifications.
- Interpret the findings The result helps compare candidates and identify obvious weaknesses but does not certify an account or storage system as secure.
Usage tips
- Length and uniqueness usually matter more than forced substitutions such as P@ssw0rd.
- Use a password manager to generate and store a different password for every service.
- Enable multi-factor authentication so a stolen password is not the only defense.
Frequently asked questions
Estimate resistance to guessing by examining length, character diversity, common patterns, dictionary matches, and predictable sequences.
Type a candidate password directly into the strength field; use a made-up example rather than a live credential on a shared device.
Review the score, estimated crack time, detected weaknesses, and suggestions rather than relying on color alone.
Crack-time estimates depend on assumptions about hashing, attacker hardware, leaks, and rate limits. They are comparative estimates, not guarantees.