Password Strength Checker

See how resistant your password is to guessing and what makes it predictable.

Analyzed locally in your browser. Your password is never sent to us.

How does this work?

PassCheckup analyzes your password using code running directly in your browser. Your password isn’t sent to PassCheckup’s servers or stored in cookies, browser storage or analytics.

Refreshing or closing the page clears the current password from the tool.

Your result will appear here as you type.

How PassCheckup evaluates passwords

Attackers don’t guess passwords at random. They start with common passwords, dictionary words and names, then try predictable variations of them. A useful password strength test has to think the same way, so PassCheckup looks for the patterns that make a password predictable instead of ticking boxes for uppercase letters, numbers and symbols.

The analysis uses zxcvbn-ts, an open-source estimator that breaks a password into its most guessable parts and estimates how many guesses each part would take. It recognizes:

  • Common passwords and familiar words, names and reversed words
  • Predictable substitutions, such as @ for a or 0 for o
  • Sequences like abc or 4321, and repeats like aaaa or abcabc
  • Keyboard patterns of adjacent keys
  • Dates and years
  • Length, and how much of it is actually unpredictable

The result is rated Very weak, Weak, Fair, Strong or Very strong, with the most important findings explained in plain language and suggestions that address them directly.

What password crack-time estimates mean

A crack-time estimate takes the estimated number of guesses a password would need and divides it by an assumed guessing speed. That speed varies enormously depending on the situation, so PassCheckup shows three example scenarios: online guessing against a service that limits login attempts, and offline attacks on stolen password hashes protected by slow or fast hashing.

Results are shown as broad ranges like “Hours” or “Centuries+” rather than precise figures. Real cracking speed depends on the hashing algorithm and its settings, the attacker’s hardware and how each service actually stores your password, none of which a checker can know. The same password can therefore look very different across scenarios.

What makes a password strong?

Strong passwords are difficult to predict, not just difficult to read. Length helps because it increases the number of possible guesses, but predictability matters too. Common words, familiar phrases, dates, sequences, keyboard patterns and repeated structures can make a password easier to guess.

A long password made from unrelated words or randomly generated characters is generally harder to guess than a shorter password built around a familiar word.

Why can P@ssw0rd123! still be predictable?

Adding capital letters, numbers and symbols doesn’t automatically make a password strong. Password-guessing tools account for common substitutions such as @ for a and 0 for o, as well as predictable additions such as 123.

What looks complicated to a person can still follow a pattern that is easy for software to recognize.

Does password length matter?

Yes. Greater length can dramatically increase guessing resistance, especially when the additional characters aren’t predictable. But length alone isn’t enough: a long familiar phrase can still be easier to guess than its length suggests.

Frequently asked questions

Is it safe to enter a password into PassCheckup?

PassCheckup analyzes passwords locally in your browser. Your password isn’t sent to our servers or stored by PassCheckup. If you prefer not to enter a password you currently use, you can test examples to learn how different patterns affect password strength.

Does PassCheckup store my password?

No. PassCheckup does not store the password you enter. Analysis happens in your browser for the current session.

How does PassCheckup measure password strength?

PassCheckup estimates how many guesses a password may require while accounting for common passwords, dictionary words, sequences, repeated patterns, keyboard patterns, predictable substitutions and other recognizable structures.

Can PassCheckup guarantee that my password is secure?

No. Password strength is an estimate of guessing resistance, not a guarantee of account security. Account security also depends on factors such as password reuse, multi-factor authentication, the security of the service and whether credentials have been exposed.

Does PassCheckup check whether my password has been leaked?

No. Password strength and breach exposure are different questions. PassCheckup evaluates how resistant a password appears to guessing; it does not check breach databases.