Skip to content

Password Strength Tester

Type a password and see how it holds up against zxcvbn, the same library used by Dropbox, Bitwarden, and 1Password. The score bar, estimated crack time, character entropy, and targeted suggestions help you understand exactly what makes a password weak or strong — all in real time, nothing leaves your browser.

  • zxcvbn score (0–4) with color-coded bar
  • Estimated crack time at 10B guesses/second
  • Character-level entropy in bits
  • Actionable warning and suggestions
  • Show/hide password toggle
  • Copy summary to clipboard

Tester

Everything stays in your browser

Score—

Crack time

—

Entropy

—

Length

—

How to test a password strength

  1. 01

    Type a password

    Start typing in the password field — the analysis updates instantly with every keystroke. Toggle Show/Hide to see what you have typed.

  2. 02

    Read the score bar

    The bar fills from 0 to 4 with a color that shifts from red (very weak) through orange, yellow, and lime to green (very strong). Each level corresponds to a clear label so you are not guessing what the colour means.

  3. 03

    Check the crack time

    The estimated time tells you how long an offline attacker with 10 billion guesses per second would need to crack the password. A password that survives "centuries" is in completely different territory from one cracked "instantly".

  4. 04

    Act on the feedback

    zxcvbn highlights what makes the password weak — common patterns, repeated characters, dictionary words — and suggests what to change. Follow the suggestions to improve the score and crack time.

What zxcvbn actually measures (and what it does not)#

zxcvbn is not a simple character-based entropy calculator. It knows about common passwords, keyboard walks (like qwerty), repeated patterns, dates, English words, common names, and other structures people actually use when creating passwords, then estimates how many guesses a smart attacker would need to find it. A password that has high character entropy but is a common pattern will score poorly, which is exactly what you want a checker to catch.

What zxcvbn does not model: slow hashes, salting, rate limiting, or account lockout. The crack-time estimates assume the attacker has the raw password or a fast hash of it — the same assumption the password-generator tool makes — so they are best read as a comparison between passwords, not a literal clock.

Why character entropy still matters#

The tool shows both the zxcvbn score and a separate character-level entropy (length × log₂(charset size)). These two numbers measure different things: zxcvbn knows what pattern the password follows, while character entropy treats every character as equally random. A randomly generated password will score high on both; a password made of two common words concatenated with a digit will score much lower on zxcvbn than its character entropy suggests, because zxcvbn recognises the words.

Looking at both numbers together gives you the most useful picture: if the zxcvbn score is telling you "very weak" but the character entropy is saying "strong", the problem is almost certainly a recognisable pattern in the password, and the feedback section will tell you exactly what.

The difference between "offline fast" and "online" crack times#

The tool shows two crack-time estimates: one assuming a fast offline attack (10 billion guesses/second) and one assuming a slow, properly-hashed scenario (10 thousand guesses/second, such as bcrypt or Argon2). The fast estimate assumes an attacker who has already obtained the password hash and is cracking it on GPU hardware with no rate limiting — the worst-case realistic scenario.

The slow estimate models a service that uses a purpose-built password hash and rate-limiting on login attempts, which is what responsible services actually do. The gap between the two numbers — often many orders of magnitude — is exactly why slow hashing exists, and why writing "password strength does not matter if the server hashes properly" is misleading: the attacker chooses which hash to attack, not the service.

Nothing leaves your browser#

zxcvbn is loaded from a CDN on first page visit, but once it is in the browser the entire analysis runs locally — no keystrokes, no passwords, and no analysis results are sent anywhere. You can disconnect from the internet after the page loads and it will keep working. The same zero-exfiltration principle applies to every tool on this site.

Frequently asked questions

Is my password sent to a server when I type it?

No. zxcvbn runs entirely in your browser after being loaded from a CDN on the first visit. Nothing you type is transmitted, logged, or stored anywhere. You can verify this by disconnecting from the internet after the page loads — the tool continues to work.

What does the score 0–4 mean?

0 means Very Weak (easily guessed), 1 is Weak, 2 is Fair, 3 is Strong, and 4 is Very Strong (resists even a smart attacker with GPU hardware). These correspond to the coloured bar from red through to green.

How is crack time estimated?

zxcvbn calculates how many guesses a smart attacker would need, then divides by a guess rate. The tool shows two scenarios: "offline fast" at 10 billion guesses/second (modern GPU hardware against a fast hash) and "offline slow" at 10 thousand guesses/second (a proper slow hash like bcrypt). The actual time depends on the attacker's hardware and the service's hash choice.

Why does a long password with random characters sometimes score lower than expected?

zxcvbn recognises patterns — repeated characters, keyboard walks, common substitutions, repeated substrings — and penalises them even if the overall length is high. A password like "correcthorsebatterystaple" is long but made of common English words, so zxcvbn will flag those words. This is a feature, not a bug: it catches exactly the kind of structure humans reach for that pure entropy calculations miss.

What is character entropy and why show it separately?

Character entropy is `length × log₂(charset size)` — it treats every character as if it were chosen uniformly at random from the detected character set. It represents the theoretical maximum strength for a password of that length and charset. Comparing it against the zxcvbn score tells you whether the password is actually using its character space efficiently or falling back on predictable patterns.

What does the feedback section tell me?

zxcvbn provides a warning about the single most important weakness it found (e.g. "This is similar to a commonly used password") and a list of actionable suggestions (e.g. "Add another word or two. Uncommon words are better."). Not every password produces feedback — strong random passwords typically have no suggestions, which is itself useful information.

Developers

UUID Generator

Generate cryptographically random UUID v4 or time-ordered UUID v7, in bulk.

Developers

Base64 Encoder & Decoder

Encode and decode Base64 with correct UTF-8 handling, including the URL-safe alphabet.

Developers

ULID Generator

Generate ULIDs — sortable by creation time like UUID v7, but Crockford Base32 instead of hex.