Password Entropy Checker
A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.
Type a password on the left.
How it works
Entropy here starts as a charset-size × length calculation — how many characters are available at each position,
raised to the number of positions, expressed in bits — and is then cut down for the patterns a guesser tries
first: one character or a short unit repeated (aaaaaaaa, abcabcabc), sequential or
repeated runs (12345, zyxw), and about a hundred of the most common passwords, with or
without a capital letter or a number on the end. Each reduction is listed with the result.
It is still not a full crack-time model like zxcvbn: it does not know dictionaries, names, most keyboard walks, or leetspeak substitutions, so a password built from a large character set can still score well while being a well-known phrase. Treat a strong rating as a ceiling, not a guarantee.
Why three crack-time estimates
The honest answer to "how long would this take to crack" depends entirely on what is defending it. An online login with rate limiting, a slow offline hash like bcrypt, and a fast unsalted hash represent wildly different attacker budgets — collapsing them into one number would hide which threat model actually applies.
Nothing here is transmitted
Nothing typed here is sent anywhere, logged, or stored — the string never leaves this function call.
Example
Going from a 10 to an 11-character password multiplies the keyspace by the full character set size; adding a fourth character class to an already-mixed password typically less than doubles it. Length is the more reliable lever for raising entropy.
Frequently asked questions
Why does adding one more character matter more than adding a symbol?
Entropy grows with the exponent (length), not the base (charset size) — going from a 10 to an 11-character password multiplies the keyspace by the full charset size, while adding a fourth character class typically less than doubles it. Length is the more reliable lever.
Why three different crack-time estimates instead of one?
Because the honest answer depends entirely on what is defending the password. An online login with rate limiting, a slow offline hash like bcrypt, and a fast unsalted hash represent wildly different attacker budgets — collapsing them into one number would hide which threat model actually applies.
Is a high entropy score enough to call a password "strong"?
No — see the limitations above. High entropy is a necessary floor, not sufficient proof; a long, high-charset password reused across sites or matching a known breach corpus is still a bad password despite scoring well here.
Related tools
Secret Pattern Detector
Scan pasted text or code for the shape of a leaked API key, token or private key.
LocalHash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalSSH Public Key Inspector
Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.
LocalIOC Extractor
Pull indicators of compromise out of any block of text, log or report.
LocalIOC Defanger
Neutralise indicators so they can be shared without becoming clickable.
LocalIOC Refanger
Restore defanged indicators to their original, machine-readable form.
Local