Analyze locally
Length, patterns, variety, and rough crack time are calculated in your browser.
Privacy-first password check
Instant strength feedback and an optional breach check—without handing your password to us.
Check a password ↓01 / Password checker
The meter reacts locally as you type. Nothing is submitted, stored, logged, or added to analytics.
Avoid typing a real password on a shared, monitored, or untrusted device.
Type a password above. The strength check runs entirely in this browser.
Next moveStart with length: aim for 14 characters or more.
We hash it here and send only the first five SHA-1 characters to Have I Been Pwned. The full password and full hash never leave.
02 / How it works
Length, patterns, variety, and rough crack time are calculated in your browser.
If you choose the breach lookup, your browser creates a SHA-1 hash on this device.
Only a five-character prefix is sent. Matching suffixes are compared here and discarded.
What we never receive
Your passwordThe full hashYour resultYour email03 / Password managers
A password manager makes unique credentials practical. Our first editorial shortlist focuses on two established options for individuals, families, and businesses.
Read the comparison guide →A polished option for families and teams that want flexible vaults, passkeys, Watchtower alerts, and a dual-key security design.
A streamlined option with XChaCha20-encrypted vaults, passkeys, password health tools, breach monitoring, and broad platform support.
04 / Password security guides
Learn how to create and change passwords safely, choose a password manager, adopt passkeys, and respond to a breach.
Explore all guides →Length, uniqueness, generators, and current NIST guidance.
Replace the credential, close sessions, and protect recovery.
Why passkeys resist phishing and where recovery still matters.
05 / Safer starting point
Four unrelated words plus a number, generated on this device with your browser’s cryptographic random number generator.
Treat generated passwords as sensitive. Save them directly to a trusted password manager.
The rules that matter
06 / Questions
No. Strength analysis is local. The optional breach lookup sends only a five-character hash prefix to the Pwned Passwords range API.
No. It is a teaching estimate. Actual time depends on hash type, hardware, rate limits, dictionary matches, and many other factors.
No. It only means the password was not found in that data set. It must still be long, unique, and protected with MFA.
Only because the Pwned Passwords range service indexes passwords by SHA-1. SHA-1 is not recommended for storing passwords, and this site stores nothing.