security-privacy
Password Strength Checker
Check password length, character variety, common values, repetition, and predictable sequences with a browser-local heuristic.
Tool workspace
The interactive tool requires JavaScript.
Instructions
Run the check and review the score, rating, detected character groups, and suggestions.
Improve length and uniqueness, remove predictable patterns, then save the final password in a trusted password manager and enable MFA where available.
Enter a draft password to receive a local heuristic score and concrete improvement suggestions. The check runs in this browser and does not upload or store the value.
Direct answer
Password Strength Checker scores length and character variety, then deducts points for common passwords, repeated characters, simple sequences, and single-character-class values. It is a browser-local estimate, not proof that a password is secure, unique, or absent from breach data.
How to use this tool
- Enter a draft password on a trusted device; avoid using a live credential if the device or browser is not under your control.
- Run the check and review the score, rating, detected character groups, and suggestions.
- Improve length and uniqueness, remove predictable patterns, then save the final password in a trusted password manager and enable MFA where available.
What the heuristic checks
The local rules consider length, lowercase and uppercase letters, digits, symbols, non-ASCII characters, well-known weak values, repeated characters, and alphabetic, numeric, or keyboard sequences.
Why length and uniqueness matter
A longer password or multi-word passphrase expands the search space, while uniqueness limits the damage from reuse. Character variety can help, but short substitutions such as P@ssw0rd remain predictable.
Important limits
The result cannot measure server-side rate limits, hashing, account recovery, phishing resistance, password reuse, or breach exposure. Treat the score as editing guidance, not certification or a guarantee.
Frequently asked questions
Is my password uploaded or saved?
No. The published checker evaluates the value in the current browser and does not intentionally send it to a server, URL, cookie, or browser storage.
Does a score of 100 prove the password is safe?
No. A high heuristic score only means the local rules found no obvious weakness. Reuse, phishing, malware, breach exposure, and weak account controls can still make it unsafe.
Does this checker search breach databases?
No. It makes no network request and cannot tell whether a password has appeared in a leak.
Should I use symbols instead of length?
Do not trade away length for forced complexity. Prefer a long, unique generated password or passphrase that satisfies the service rules.
Last updated: