Security

Password Strength Meter

See how strong a password really is — a 0–100 score, entropy in bits, an estimated time to crack and the patterns that make it easy to guess. Everything runs on your device.

Check a password

Checked on your device as you type. Nothing is saved, logged or sent anywhere.

Try an example

Strength analysis

No password entered
Enter a password to see how strong it is

Password strength levels

  • Very weak (0–19)

    Common passwords and simple sequences. Cracked instantly.

    e.g. 123456, password

  • Weak (20–39)

    Too short, or a common word with a few digits. Falls to a basic attack quickly.

    e.g. pakistan123, qwerty123

  • Medium (40–59)

    Some length and variety, but predictable tricks attackers already try.

    e.g. P@ssw0rd!, Summer2026!

  • Strong (60–79)

    Good length and a mix of character types. Hard to brute force.

    e.g. kT9#vQ2$wZ

  • Very strong (80–100)

    Long, random and varied — or a long random passphrase.

    e.g. xK8#qP$2mL9!vR5&

  • Entropy in bits

    How many guesses a brute-force attack would need, based on length and character types.

  • Time to crack

    A plain-English estimate, from “less than a second” to “longer than the age of the universe”.

  • Specific tips

    Flags common passwords, sequences, keyboard runs and repeats, and tells you what to change.

How strong is your password?

Type or paste a password to get an instant score out of 100 with clear feedback. It's useful for checking an old password, or for showing friends and family why pakistan123isn't a good idea.

What makes a password strong

  • Length: every extra character multiplies the work for an attacker. Aim for 12 or more.
  • Variety: mix lowercase, uppercase, numbers and symbols.
  • Randomness: avoid names, dates, sequences like 123 and keyboard runs like qwerty.
  • Uniqueness: never reuse a password. One leak then unlocks every account that shares it.

How the numbers are worked out

Entropy is length × log₂(pool size), where the pool is the set of character types used: 26 lowercase, 26 uppercase, 10 digits and 33 symbols (including space). That's an upper bound — it assumes every character was picked at random, which is rarely true of passwords people make up.

Time to crack is how long it would take to try every combination at 10 billion guesses per second — roughly an attacker with GPUs working on a leaked database of fast, unsalted hashes. Common passwords are marked “Instantly”, because attackers try lists of them first. Patterns such as sequences and repeats make real-world cracking faster than the estimate.

Tips

  • Use a passphrase of several random words, or a random password from a generator.
  • Keep your passwords in a password manager so each one can be long and unique.
  • Turn on two-factor authentication for email, banking and social accounts.
  • Change a password straight away if a site you use reports a breach.

Your password is analysed entirely in your browser. It isn't sent to a server, saved or logged — you can confirm this in your browser's network tab.

Private by design. Everything runs in your browser — nothing you enter is uploaded or stored by AISeekho.