How to check your password strength
- Type or paste a password into the Password to check box. Use the eye button to show or hide what you typed.
- Read the Strength result – a coloured bar and a score from Very weak to Very strong, updated as you type.
- Look at the estimates: the number of guesses needed and the time to crack it in three attack scenarios.
- Review Weak spots and How to make it stronger for the exact patterns found and what to change.
- Press Clear when you're done, or open the password generator to create a new one.
Features
- Pattern detection for common passwords, common words and names, leetspeak, reversed words, keyboard runs, sequences, repeats, years and dates.
- Score from 0 to 4 with an estimated number of guesses.
- Three crack-time estimates: a throttled online attack, an offline attack on slow hashes and an offline attack on fast hashes.
- Specific warnings and tips based on what was found, not generic rules.
- Character breakdown showing length and which types of characters are used.
- Show or hide toggle and a Clear button.
- Private by design: no network requests with your input, no storage, no breach lookup.
Why use Fileora's password strength checker
Simple meters count character types and length, so they rate Password1! as strong because it ticks every box. Here it scores Weak, because it is a leaked password with a capital letter and a symbol added in the most expected places. Real attackers don't guess character by character – they start with leaked password lists, dictionary words, keyboard patterns and dates, then add common tweaks. This checker estimates strength the same way, so a predictable password is flagged even when it looks complex.
Because everything runs on your device, you can test ideas without sending them anywhere. It's free, needs no account and works on mobile.
What the crack times really mean
A website that locks accounts or slows down after failed logins limits an online attacker to a trickle of guesses, so even a modest password can survive for a while. The real danger is a data breach: once password hashes are stolen, attackers guess offline as fast as their hardware allows. With a slow, salted hash like bcrypt or Argon2 that's thousands of guesses a second; with a fast hash like MD5 or SHA-1 on graphics cards it can be billions. You rarely know how a site stores passwords, so aim for a password that holds up in the fast-hash column.
Tips for strong passwords
- Go long: 14 or more characters, or a passphrase of four or more random words such as “velvet cactus orbit lantern”.
- Avoid personal details – names, birthdays, anniversaries, pets and places are the first guesses of anyone who knows you.
- Don't rely on swaps like @ for a or 0 for o; they are tried automatically.
- One password per account, so a leak on one site doesn't open the others.
- Use a password manager and turn on two-factor authentication wherever it's offered.
The easiest way to get a password that scores well is to let a computer choose it: the password generator creates random passwords with the characters you pick. To see how passwords are hashed, try the hash generator, and to protect a document with a password, use lock PDF.