Skip to content

Password Strength Checker – Test How Secure a Password Is

Type a password to see a strength score from 0 to 4, an estimate of how many guesses it would take, rough crack times for different attacks and specific tips to improve it. The check runs only in your browser.

Your password never leaves this page: the check runs in your browser, with no network requests and nothing saved. It is cleared when you close the tab.

Start typing to see how strong the password is.

This tool estimates how hard a password is to guess. It does not check whether the password has appeared in a data breach.

How to check your password strength

  1. Type or paste a password into the Password to check box. Use the eye button to show or hide what you typed.
  2. Read the Strength result – a coloured bar and a score from Very weak to Very strong, updated as you type.
  3. Look at the estimates: the number of guesses needed and the time to crack it in three attack scenarios.
  4. Review Weak spots and How to make it stronger for the exact patterns found and what to change.
  5. Press Clear when you're done, or open the password generator to create a new one.

Features

  • Pattern detection for common passwords, common words and names, leetspeak, reversed words, keyboard runs, sequences, repeats, years and dates.
  • Score from 0 to 4 with an estimated number of guesses.
  • Three crack-time estimates: a throttled online attack, an offline attack on slow hashes and an offline attack on fast hashes.
  • Specific warnings and tips based on what was found, not generic rules.
  • Character breakdown showing length and which types of characters are used.
  • Show or hide toggle and a Clear button.
  • Private by design: no network requests with your input, no storage, no breach lookup.

Why use Fileora's password strength checker

Simple meters count character types and length, so they rate Password1! as strong because it ticks every box. Here it scores Weak, because it is a leaked password with a capital letter and a symbol added in the most expected places. Real attackers don't guess character by character – they start with leaked password lists, dictionary words, keyboard patterns and dates, then add common tweaks. This checker estimates strength the same way, so a predictable password is flagged even when it looks complex.

Because everything runs on your device, you can test ideas without sending them anywhere. It's free, needs no account and works on mobile.

What the crack times really mean

A website that locks accounts or slows down after failed logins limits an online attacker to a trickle of guesses, so even a modest password can survive for a while. The real danger is a data breach: once password hashes are stolen, attackers guess offline as fast as their hardware allows. With a slow, salted hash like bcrypt or Argon2 that's thousands of guesses a second; with a fast hash like MD5 or SHA-1 on graphics cards it can be billions. You rarely know how a site stores passwords, so aim for a password that holds up in the fast-hash column.

Tips for strong passwords

  • Go long: 14 or more characters, or a passphrase of four or more random words such as “velvet cactus orbit lantern”.
  • Avoid personal details – names, birthdays, anniversaries, pets and places are the first guesses of anyone who knows you.
  • Don't rely on swaps like @ for a or 0 for o; they are tried automatically.
  • One password per account, so a leak on one site doesn't open the others.
  • Use a password manager and turn on two-factor authentication wherever it's offered.

The easiest way to get a password that scores well is to let a computer choose it: the password generator creates random passwords with the characters you pick. To see how passwords are hashed, try the hash generator, and to protect a document with a password, use lock PDF.

Frequently asked questions

Is it safe to type my password here?

The check runs entirely in your browser. The page makes no network request with what you type and saves nothing, not even in local storage, and the field is empty again when you reload. Even so, a good habit is to test a password that is similar in style to your real one rather than the real one itself.

How is the strength worked out?

The checker looks for the patterns attackers try first: about 200 of the most common leaked passwords, common words and names, leetspeak such as P@ssw0rd, words spelled backwards, keyboard runs like qwerty or 1qaz, sequences like abcd or 4321, repeats, years and dates. It then finds the cheapest way to guess the whole password from those pieces, with any leftover characters guessed by brute force, and turns that into a score from 0 (very weak) to 4 (very strong).

Why does my complex-looking password get a low score?

Length only helps when the characters are unpredictable. Summer2025! has 11 characters with uppercase, numbers and a symbol, yet it only scores Fair because it's a common word with a capital first letter, a recent year and an exclamation mark at the end – exactly the shape crackers try early. A random mix or a passphrase of unrelated words does far better.

What do the three crack times mean?

They show how long it could take to try the estimated number of guesses at three speeds: about 100 guesses an hour against a website that limits logins, about 10,000 a second against stolen passwords stored with a slow hash like bcrypt, and about 10 billion a second against a fast hash like MD5. They are rough orders of magnitude, not promises.

Does this check whether my password has been leaked in a breach?

No. It only estimates how hard the password is to guess. It doesn't look the password up in any breach database, because that would require contacting an outside service.

What makes a password strong?

Length and unpredictability. Aim for at least 14 characters that don't follow a pattern, or four or more random words, and use a different password for every account. A password manager makes that practical.

Can a strong score be wrong?

Yes. The checker doesn't know personal details such as your pet's name, your street or your team, and its word list is small. A password built from things people know about you can score well here and still be easy for them to guess.

Can't find the tool you need, or something isn't working?

Tell us which tool you'd like next or what went wrong. We read every message, and requests decide what we build next.

Opens your email app. Please don't attach private files.