Password Strength Checker: How It Works
Password strength is not about complexity rules — it is about how many guesses an attacker needs. This checker estimates that number, and this page explains why the rules most organisations enforce actively make passwords weaker.
Entropy is what matters
Strength is measured in bits of entropy, which is the base-2 logarithm of the number of possible passwords an attacker would have to search.
| Entropy | Possibilities | Verdict |
|---|---|---|
| Under 28 bits | < 270 million | Very weak — instant |
| 28–35 bits | Up to 34 billion | Weak |
| 36–59 bits | Up to 5.7 × 10¹⁷ | Reasonable |
| 60–127 bits | Very large | Strong |
| 128+ bits | Astronomical | Excellent |
Length beats complexity
Each additional character multiplies the search space; each additional character class only widens the base. The arithmetic is decisive:
| Password | Length | Entropy |
|---|---|---|
P@ssw0rd! | 9 | ≈ 28 bits, and far less in practice |
correct horse battery staple | 28 | ≈ 44 bits from a 7,776-word list |
Tr0ub4dor&3 | 11 | ≈ 28 bits |
P@ssw0rd! satisfies almost every corporate complexity policy and is in every cracking dictionary. The substitutions — @ for a, 0 for o, ! appended — are the first transformations any cracking tool applies. A policy that demands them produces predictable passwords, which is why NIST guidance since 2017 has recommended dropping composition rules and encouraging length instead.
How attacks actually work
Attackers do not try every combination alphabetically. They try, in order:
- Known breached passwords — billions are publicly available.
- Dictionary words with common substitutions and appended digits.
- Patterns — keyboard walks, dates, names plus years.
- Brute force, only as a last resort.
This is why a password's real strength is often far below its theoretical entropy. Any password that has appeared in a breach has an effective strength of zero, regardless of how complex it looks.
What actually protects an account
- Unique passwords everywhere. Reuse means one breached site compromises all the others — the most common cause of account takeover by a wide margin.
- A password manager. It makes unique random passwords practical, which nothing else does.
- Two-factor authentication. An app-based or hardware key second factor protects the account even if the password leaks. SMS is weaker but far better than nothing.
- Passkeys, where offered — there is no shared secret to steal or phish.
What not to do
Do not paste a password you actually use into any online checker, including this one. Use a similar structure rather than the real thing. This tool evaluates entirely in your browser and transmits nothing, but that is not true of every checker, and the habit is worth keeping regardless.