Menu

Password Strength Checker

Password Strength Checker: How It Works

Password strength is not about complexity rules — it is about how many guesses an attacker needs. This checker estimates that number, and this page explains why the rules most organisations enforce actively make passwords weaker.

Entropy is what matters

Strength is measured in bits of entropy, which is the base-2 logarithm of the number of possible passwords an attacker would have to search.

EntropyPossibilitiesVerdict
Under 28 bits< 270 millionVery weak — instant
28–35 bitsUp to 34 billionWeak
36–59 bitsUp to 5.7 × 10¹⁷Reasonable
60–127 bitsVery largeStrong
128+ bitsAstronomicalExcellent

Length beats complexity

Each additional character multiplies the search space; each additional character class only widens the base. The arithmetic is decisive:

PasswordLengthEntropy
P@ssw0rd!9≈ 28 bits, and far less in practice
correct horse battery staple28≈ 44 bits from a 7,776-word list
Tr0ub4dor&311≈ 28 bits

P@ssw0rd! satisfies almost every corporate complexity policy and is in every cracking dictionary. The substitutions — @ for a, 0 for o, ! appended — are the first transformations any cracking tool applies. A policy that demands them produces predictable passwords, which is why NIST guidance since 2017 has recommended dropping composition rules and encouraging length instead.

How attacks actually work

Attackers do not try every combination alphabetically. They try, in order:

  1. Known breached passwords — billions are publicly available.
  2. Dictionary words with common substitutions and appended digits.
  3. Patterns — keyboard walks, dates, names plus years.
  4. Brute force, only as a last resort.

This is why a password's real strength is often far below its theoretical entropy. Any password that has appeared in a breach has an effective strength of zero, regardless of how complex it looks.

What actually protects an account

What not to do

Do not paste a password you actually use into any online checker, including this one. Use a similar structure rather than the real thing. This tool evaluates entirely in your browser and transmits nothing, but that is not true of every checker, and the habit is worth keeping regardless.

Frequently Asked Questions

Is P@ssw0rd! a strong password?
No. It satisfies most complexity policies and appears in every cracking dictionary. Character substitutions like @ for a and 0 for o are the first transformations attackers try, so they add essentially nothing.
Is length or complexity more important?
Length, decisively. Each extra character multiplies the search space, while adding a character class only widens the base slightly. A long passphrase beats a short complex string by a wide margin.
Should I change passwords regularly?
Current guidance says no, unless there is evidence of compromise. Forced rotation causes people to make small predictable changes, which weakens security rather than improving it. Change immediately if a breach is suspected.
Are password managers safe?
Far safer than the alternative. The risk of a single well-encrypted vault is much lower than the risk of reused or weak passwords across dozens of sites. Protect it with a long unique master password and two-factor authentication.
What is the strongest single step I can take?
Enabling two-factor authentication on important accounts. It protects you even if the password is stolen, phished or leaked in a breach — which is the scenario that actually happens.
Is it safe to type my real password here?
This tool evaluates entirely in your browser and transmits nothing. Even so, the safer habit is to test a password of similar structure rather than one you actually use — not every online checker works locally.

Related Security Tools

Browse all Security tools →