See how long your password would really survive an attack, and whether that exact password is already on a breach list.
Strength is calculated on your device. The leak check sends only the first five characters of a hash, never the password.
Most password meters count character types and call anything with a capital, a number and a symbol strong. Attack software does not guess that way. It starts with the most common passwords, then dictionary words with predictable substitutions, then names, dates and keyboard patterns. A password like Summer2024! ticks every box on a naive meter and falls in seconds.
This checker thinks like the attacker. It looks for the patterns cracking tools try first and gives a realistic estimate of how long your password would last, under four different kinds of attack. Then it checks whether that exact password already appears in a known breach, which matters more than any strength score.
After a breach, criminals rarely attack the breached site again. They take the email and password pairs and try them against email providers, banks, shops and streaming services. This is credential stuffing, and it works because most people reuse passwords. One leaked password on a forgotten forum becomes access to an inbox, and the inbox is the password reset path for everything else.
When a breached company stored passwords as hashes, attackers download the dump and run cracking software offline, with no lockouts and no rate limits. Common passwords fall in the first second. Pattern based passwords fall within hours. Long, random or passphrase style passwords are the ones that survive, which is why length does more than complexity.
A leak check tells you whether a specific password is already burned. If it is, the fix is not to add a character. It is to replace it everywhere it was used with a unique password, which is only practical with a password manager.
Two factor authentication is the backstop. Even a leaked password is much less useful to an attacker when the account also needs a code from an app or a security key.
Here, yes. The strength analysis runs entirely in your browser and nothing is sent until you press the leak check. Even then only the first five characters of a SHA-1 hash leave your device, and the matching happens locally, so the service cannot tell which password you checked. As a general rule, only use checkers that explain exactly this.
Length and unpredictability. Four or five random unrelated words, or 16 or more random characters from a password manager, beat a short password full of symbols. Avoid anything based on names, dates, keyboard patterns, or a dictionary word with letters swapped for numbers, because cracking tools try all of those first.
For accounts you care about, aim for at least 16 characters if random, or at least four random words for a passphrase. Your email, bank and password manager deserve more. Current guidance from NIST puts the emphasis on length over complexity rules.
That exact password appears in a breach dataset. It does not necessarily mean your account was breached, since someone else may have used the same password, but it does mean attackers already have it on their lists. Stop using it everywhere and replace it with a unique one.
Mostly offline, after stealing a database of hashed passwords. Software tries billions of guesses a second, starting with known leaked passwords, then dictionary words with common changes, then patterns. Brute forcing every combination is the last resort, and only works on short passwords.
Yes, for almost everyone. The main danger is reuse, not weak passwords, and nobody can remember a unique strong password for a hundred accounts. A manager generates and fills them, so each breach only exposes one account.