Skip to main content
QUIETLYTIC
Cybersecurity

Password Entropy Checker

A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.

Local · nothing leaves this browser Type a password to estimate
Esc Clear
Entropy estimate

Type a password on the left.

How it works

Entropy here starts as a charset-size × length calculation — how many characters are available at each position, raised to the number of positions, expressed in bits — and is then cut down for the patterns a guesser tries first: one character or a short unit repeated (aaaaaaaa, abcabcabc), sequential or repeated runs (12345, zyxw), and about a hundred of the most common passwords, with or without a capital letter or a number on the end. Each reduction is listed with the result.

It is still not a full crack-time model like zxcvbn: it does not know dictionaries, names, most keyboard walks, or leetspeak substitutions, so a password built from a large character set can still score well while being a well-known phrase. Treat a strong rating as a ceiling, not a guarantee.

Why three crack-time estimates

The honest answer to "how long would this take to crack" depends entirely on what is defending it. An online login with rate limiting, a slow offline hash like bcrypt, and a fast unsalted hash represent wildly different attacker budgets — collapsing them into one number would hide which threat model actually applies.

Nothing here is transmitted

Nothing typed here is sent anywhere, logged, or stored — the string never leaves this function call.

Example

Going from a 10 to an 11-character password multiplies the keyspace by the full character set size; adding a fourth character class to an already-mixed password typically less than doubles it. Length is the more reliable lever for raising entropy.

Frequently asked questions

Why does adding one more character matter more than adding a symbol?

Entropy grows with the exponent (length), not the base (charset size) — going from a 10 to an 11-character password multiplies the keyspace by the full charset size, while adding a fourth character class typically less than doubles it. Length is the more reliable lever.

Why three different crack-time estimates instead of one?

Because the honest answer depends entirely on what is defending the password. An online login with rate limiting, a slow offline hash like bcrypt, and a fast unsalted hash represent wildly different attacker budgets — collapsing them into one number would hide which threat model actually applies.

Is a high entropy score enough to call a password "strong"?

No — see the limitations above. High entropy is a necessary floor, not sufficient proof; a long, high-charset password reused across sites or matching a known breach corpus is still a bad password despite scoring well here.

Related tools

From the intelligence desk