1. Estimate entropy and crack time
Entropy is estimated from length and character classes, then shown as offline brute-force and online rate-limited time scales. Length under 8, too few classes, or keyboard sequences pull the grade down.
Type as soon as the page opens. This tab estimates strength, flags weak patterns, and compares a built-in list of common leaked passwords. Your password is not uploaded. This is not a Have I Been Pwned search.
Grade, entropy, and crack-time estimates update as you type. The weak-password list loads on this device. The password you type never leaves this tab.
Masked by default. Nothing is written to local storage or sent to a server.
Loading the weak-password list…
Nothing to score yet. After you type, you will see Weak / Medium / Strong / Very strong, plus whether it matches a public leaked-password list.
Estimated entropy —
Do not keep using a weak password. Open the Password Generator and create a new one on this device.
First the makeup and brute-force cost, then a local weak-password list. Both steps stay in this tab. No external breach API is called.
Entropy is estimated from length and character classes, then shown as offline brute-force and online rate-limited time scales. Length under 8, too few classes, or keyboard sequences pull the grade down.
The list downloads with the page. Matching covers exact text, case changes, trailing digits, and common leet variants. A hit is marked weak with a very-high-risk warning.
It can catch widely abused passwords. It cannot prove a password never appeared in any breach. This page does not query Have I Been Pwned and does not send the password out.
Password Audit only answers how strong this string looks right now. Thresholds, list coverage, and the limits of a local check are written below.
Entropy, weak patterns, and list matching all run in the browser. The password does not enter an HTTP request and is not written to analytics. Closing the tab leaves no copy of this input on the device.
Estimated entropy ≥ 80 bits is Very strong, ≥ 60 is Strong, ≥ 40 is Medium, and the rest is Weak. Length under 8, a common weak password, or a public-list hit is forced to Weak.
The check uses a built-in list of frequently leaked weak passwords, not a web-wide dump set. Strings longer than 128 characters get an exact match only—no trailing-digit or leet variants.
It cannot prove a password was never leaked, and it does not replace a password manager. Use it to drop obviously weak passwords on the spot. Create a new one with the Password Generator on this device.
This one does not. Entropy, weak-pattern checks, and the common-password list all run in this tab. The password is not sent in a request and is not written to analytics.
This page is not a Have I Been Pwned lookup. It estimates strength on this device and compares a built-in list of frequently leaked weak passwords. A miss does not prove the password never appeared in any breach.
Entropy estimates how hard a brute-force search would be. Longer strings and more character classes usually raise it. Passwords shorter than 8 characters, common weak passwords, or list hits are marked weak even if they look long.
Use the password generator to create a new password on this device. Do not reuse it on important accounts. To send it to a colleague, use a Burn-Link that is destroyed after one open.
Generate a new one, send it once, or clean outbound text without leaving this site.
Create a 6–128 character random password or a memorable passphrase on this device. Plaintext is not uploaded, and there is no password vault.
Send a new password once. Ciphertext is stored briefly; the key stays in the URL # fragment and is burned after reading.
Before you send a chat log or ticket, strip tracking parameters and mask phone numbers and ID numbers.