AUDIT

Password strength checker: local rating, not a breach lookup

Type as soon as the page opens. This tab estimates strength, flags weak patterns, and compares a built-in list of common leaked passwords. Your password is not uploaded. This is not a Have I Been Pwned search.

✓ Local entropy ✓ Common-password list ✓ Nothing uploaded ✓ No account
01

Type a password and see how strong it is

Grade, entropy, and crack-time estimates update as you type. The weak-password list loads on this device. The password you type never leaves this tab.

Masked by default. Nothing is written to local storage or sent to a server.

Loading the weak-password list…

This check

Grade and risk update as you type

Nothing to score yet. After you type, you will see Weak / Medium / Strong / Very strong, plus whether it matches a public leaked-password list.

02

How this password strength checker scores — and why it is not HIBP

First the makeup and brute-force cost, then a local weak-password list. Both steps stay in this tab. No external breach API is called.

1. Estimate entropy and crack time

Entropy is estimated from length and character classes, then shown as offline brute-force and online rate-limited time scales. Length under 8, too few classes, or keyboard sequences pull the grade down.

2. Compare a local weak-password list

The list downloads with the page. Matching covers exact text, case changes, trailing digits, and common leet variants. A hit is marked weak with a very-high-risk warning.

3. This is not a web-wide dump check

It can catch widely abused passwords. It cannot prove a password never appeared in any breach. This page does not query Have I Been Pwned and does not send the password out.

03

What this checker measures — and what it cannot prove

Password Audit only answers how strong this string looks right now. Thresholds, list coverage, and the limits of a local check are written below.

Where it runs

Entropy, weak patterns, and list matching all run in the browser. The password does not enter an HTTP request and is not written to analytics. Closing the tab leaves no copy of this input on the device.

Grade thresholds

Estimated entropy ≥ 80 bits is Very strong, ≥ 60 is Strong, ≥ 40 is Medium, and the rest is Weak. Length under 8, a common weak password, or a public-list hit is forced to Weak.

List coverage

The check uses a built-in list of frequently leaked weak passwords, not a web-wide dump set. Strings longer than 128 characters get an exact match only—no trailing-digit or leet variants.

What it cannot do

It cannot prove a password was never leaked, and it does not replace a password manager. Use it to drop obviously weak passwords on the spot. Create a new one with the Password Generator on this device.

FAQ

Password strength checker FAQ

This one does not. Entropy, weak-pattern checks, and the common-password list all run in this tab. The password is not sent in a request and is not written to analytics.

This page is not a Have I Been Pwned lookup. It estimates strength on this device and compares a built-in list of frequently leaked weak passwords. A miss does not prove the password never appeared in any breach.

Entropy estimates how hard a brute-force search would be. Longer strings and more character classes usually raise it. Passwords shorter than 8 characters, common weak passwords, or list hits are marked weak even if they look long.

Use the password generator to create a new password on this device. Do not reuse it on important accounts. To send it to a colleague, use a Burn-Link that is destroyed after one open.