PassGen.co

Language

Password Strength Checker

  • See how long it would take to crack, and whether it has leaked.

Your password never leaves this device. How it stays private

Free Password Strength Checker

Test how secure your password is. Type or paste it above to see how strong it is, how long it would take to crack, and whether it is one of the million most-leaked passwords. It all happens in your browser as you type, and the password never leaves this device.

For the full picture, tap Check all known breaches. It looks the password up among every leaked password that Have I Been Pwned knows of, while sending only 5 characters of a scrambled fingerprint, never the password. See exactly what is sent.

Jump to: Looks strong, isn’t · What the result means · What is sent · If it is weak · Questions

Looks Strong, Isn’t

Most checkers count length and kinds of character, so they love a password like P@ssw0rd2024!. Cracking tools don’t count; they try the patterns people use, and they try them first. Here is what this checker says about some passwords that look fine:

  • P@ssw0rd2024!WeakA word, look-alike swaps, a year, and a symbol: cracked in under a second
  • Password123!LeakedFound in data breaches about 300,000 times
  • qwertyuiop123LeakedA keyboard row and a count: about 650,000 times
  • Liverpool1892LeakedA team and its founding year: about 27,000 times
  • Tr0ub4dor&3WeakThe xkcd comic’s example, now on every cracking list
  • k7#Rq!9vT$2m@LxVery strongRandom: 63 billion years to crack

To get there, the checker uses zxcvbn, an open-source estimator from Dropbox, plus our own lists. It looks for common passwords (also with look-alike swaps), words and names (also backwards), keyboard rows, repeats, dates, and the classic word-plus-number-plus-symbol. Anything left counts as random characters. A phrase of random words is scored exactly as our passphrase generator scores it, and a phrase you made up never scores higher than the same number of random words.

No checker knows what only you know: whether it is your pet’s name, or whether you use it on other sites. A checker can show that a password is weak. It cannot prove that one is safe.

What the Result Means

The time to crack assumes the worst case: someone has stolen a copy of the hashed password and has graphics cards making 100 billion guesses a second. Guessing through a sign-in page is millions of times slower, but you can’t know how a site stores your password, so plan for the worst.

ResultAverage time to crackWhat to do
WeakLess than a dayChange it now, everywhere you use it
FairLess than 100 yearsReplace it when you next sign in
StrongLess than a million yearsFine for most accounts
Very strongA million years or moreFine for anything

A password found in a data breach is unsafe whatever its strength, because attackers try leaked passwords before anything else. That is why the checker shows Leaked instead of a strength for those.

What Is Sent When You Check for Breaches

Nothing while you type. When you tap Check all known breaches, this is what happens, using the password password as the example:

  1. You type the passwordpasswordstays on your device
  2. Your browser turns it into a SHA-1 fingerprint5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8stays on your device
  3. Only the first 5 characters go to Have I Been Pwned5BAA6sent
  4. It sends back every leaked fingerprint that starts the same way, about 2,000, mixed with dummiesyour browser looks for the match

The service never sees the password or its full fingerprint, so it can’t tell which of those 2,000 you checked.

  • The quick leak check is on your device. The page downloads, once, a compact list of fingerprints of the million most-leaked passwords, so the check as you type needs no request at all. A false match is about one in a million.
  • Nothing is sent while you type. Some checkers send a lookup on every keystroke, which together give the password away one character at a time.
  • Nothing is kept. The password is never stored, never put in the address bar, and gone when you leave the page.
  • Check it yourself. Open the Network tab of your browser’s developer tools and type: nothing goes out. Tap the button and you will see one request, to api.pwnedpasswords.com, ending in the 5 characters shown in this section after a check. Or disconnect from the internet: everything except the full breach check keeps working.

Leaked-password data: Pwned Passwords by Have I Been Pwned, used under the Creative Commons Attribution 4.0 license.

If Your Password Is Weak or Leaked

  • Change it on every site where you use it, starting with your email, because email resets everything else.
  • Make a new one rather than tweaking the old one. Adding a character or changing 1 to 2 is the first thing attackers try. Make a random password or a passphrase.
  • Use a password manager, so every account can have its own password without you remembering any of them.
  • Turn on two-step verification wherever it is offered. It keeps an account safe even if the password leaks.

Frequently Asked Questions

What is the safest password checker?

One that sends nothing while you type and lets you prove it. This page checks strength and the million most-leaked passwords on your device, and the full breach check sends only 5 characters of a fingerprint, only when you tap it. You can watch it in your browser’s Network tab, or disconnect from the internet and see the checker keep working.

How do I check if my password has been leaked?

Type or paste it above. If it is one of the million most-leaked passwords, you see it straight away. To check every known breach, tap Check all known breaches. If it appears at all, stop using it.

Is Have I Been Pwned safe to use?

Yes, for passwords. Its password check is built so it never receives your password: your browser sends only the first 5 characters of the password’s fingerprint, and does the final comparison itself. This page also asks for dummy entries in the answer, so even its size gives nothing away.

Which password is the most hacked?

123456, found in data breaches over 210 million times, followed by 123456789, 12345678, password, and qwerty (figures from Have I Been Pwned). Anything a person can think of quickly is on the lists.

Can you give me an example of a strong password?

Any example you have seen published is no longer strong, because it is now on the lists. Even correcthorsebatterystaple from the xkcd comic has turned up in breaches thousands of times. A strong password is one made at random just for you: use the password generator or the passphrase generator.

How long would it take to crack my password?

Type it above and the checker shows the average time, assuming the worst case: a stolen copy of the hashed password and 100 billion guesses a second. A random 8-character password falls in hours. A random 16-character one takes longer than the age of the universe.

Why does a long password still show as weak?

Because it contains a pattern: a common password, a keyboard row, a repeat, or a word with a number on the end. Length only helps when the characters are unpredictable.

Where can I see which of my saved passwords are compromised?

Your password manager can check them all at once. On an iPhone or a Mac, open the Passwords app and look under Security. In Chrome, Google Password Manager has Password Checkup. Bitwarden, 1Password, and most other password managers have a similar report.

How long should a password be?

At least 16 random characters, or six random words. NIST, a US standards agency, tells websites to accept passwords of at least 64 characters and to require at least 15 when the password is the only thing protecting the account.