Password Strength and Leak Checker

See how long your password would really survive an attack, and whether that exact password is already on a breach list.

Strength is calculated on your device. The leak check sends only the first five characters of a hash, never the password.

Most password meters count character types and call anything with a capital, a number and a symbol strong. Attack software does not guess that way. It starts with the most common passwords, then dictionary words with predictable substitutions, then names, dates and keyboard patterns. A password like Summer2024! ticks every box on a naive meter and falls in seconds.

This checker thinks like the attacker. It looks for the patterns cracking tools try first and gives a realistic estimate of how long your password would last, under four different kinds of attack. Then it checks whether that exact password already appears in a known breach, which matters more than any strength score.

How it works

  1. As you type, the password is analysed inside your browser. It is never sent to our server, never stored and never logged.
  2. The analyser searches for common passwords, dictionary words, names, keyboard walks such as qwerty, repeated or sequential characters, years and dates, and letter-for-number swaps such as p4ssw0rd.
  3. Each pattern found reduces the effective strength to what an attacker would actually need to search, measured in bits.
  4. That strength is converted into a time to crack at four attack speeds, from a rate limited login page to a GPU rig working on a stolen database.
  5. When you press the leak check, your browser computes a SHA-1 hash of the password and sends only the first five characters to the Pwned Passwords service.
  6. The service replies with every breached hash that starts with those five characters, several hundred of them, padded with decoys. Your browser looks for your full hash in that list locally, so no one else can tell which password you checked.

Reading your results

  • The five segment meter and label run from Very weak to Very strong. They reflect the patterns found, not just length or character types.
  • Bits of strength is the size of the search an attacker needs. Every extra bit doubles it. Under about 36 bits is weak, 60 is reasonable for most accounts, and 80 or more is very strong.
  • The headline time assumes a stolen database hashed with a fast algorithm and cracked on a GPU rig at 10 billion guesses a second. That is the realistic threat after a breach, which is why it is the number shown first.
  • Online attack, rate limited: a login page that locks you out after a few tries. Almost any password survives this, which is why it is not the number to rely on.
  • Stolen database, slow hash: sites that store passwords properly with an algorithm like bcrypt slow attackers dramatically, but you cannot tell from outside which sites do this.
  • Seen N times in known breaches means that exact password is in the public breach corpus. Attackers try these lists before anything else, so a leaked password is weak regardless of its score.
  • Not found in known breaches only means it is not in the public lists. A weak password that has never leaked can still be guessed quickly.

How this fits into the real world

After a breach, criminals rarely attack the breached site again. They take the email and password pairs and try them against email providers, banks, shops and streaming services. This is credential stuffing, and it works because most people reuse passwords. One leaked password on a forgotten forum becomes access to an inbox, and the inbox is the password reset path for everything else.

When a breached company stored passwords as hashes, attackers download the dump and run cracking software offline, with no lockouts and no rate limits. Common passwords fall in the first second. Pattern based passwords fall within hours. Long, random or passphrase style passwords are the ones that survive, which is why length does more than complexity.

A leak check tells you whether a specific password is already burned. If it is, the fix is not to add a character. It is to replace it everywhere it was used with a unique password, which is only practical with a password manager.

Two factor authentication is the backstop. Even a leaked password is much less useful to an attacker when the account also needs a code from an app or a security key.

Who this is for

  • Anyone choosing a new password who wants to know if it is actually good.
  • People who got a breach notice and want to know whether a password they still use is on the lists.
  • Anyone auditing old passwords before moving them into a password manager.
  • Parents and teachers showing why password123 and P@ssw0rd are the same password to an attacker.

What this tool cannot tell you

  • It cannot know how a particular website stores your password, which changes the real crack time dramatically.
  • The leak check covers the public breach corpus. Passwords stolen in breaches that were never published will not show up.
  • Time estimates are for a determined offline attacker. A targeted attacker who knows personal details such as your children's names can do better than generic patterns.
  • It checks one password at a time and does not check whether you have reused it. Reuse is the bigger risk and only you know where a password is used.
  • Checking a password here is safe, but you should still not paste real passwords into tools you do not trust. This page tells you exactly what leaves your browser so you can judge.

Frequently asked questions

Is it safe to type my password into a password checker?

Here, yes. The strength analysis runs entirely in your browser and nothing is sent until you press the leak check. Even then only the first five characters of a SHA-1 hash leave your device, and the matching happens locally, so the service cannot tell which password you checked. As a general rule, only use checkers that explain exactly this.

What makes a password strong?

Length and unpredictability. Four or five random unrelated words, or 16 or more random characters from a password manager, beat a short password full of symbols. Avoid anything based on names, dates, keyboard patterns, or a dictionary word with letters swapped for numbers, because cracking tools try all of those first.

How long should a password be?

For accounts you care about, aim for at least 16 characters if random, or at least four random words for a passphrase. Your email, bank and password manager deserve more. Current guidance from NIST puts the emphasis on length over complexity rules.

What does it mean if my password has been pwned?

That exact password appears in a breach dataset. It does not necessarily mean your account was breached, since someone else may have used the same password, but it does mean attackers already have it on their lists. Stop using it everywhere and replace it with a unique one.

How do hackers actually crack passwords?

Mostly offline, after stealing a database of hashed passwords. Software tries billions of guesses a second, starting with known leaked passwords, then dictionary words with common changes, then patterns. Brute forcing every combination is the last resort, and only works on short passwords.

Should I use a password manager?

Yes, for almost everyone. The main danger is reuse, not weak passwords, and nobody can remember a unique strong password for a hundred accounts. A manager generates and fills them, so each breach only exposes one account.

Related tools

Guides that go with this tool