Privacy-first password check

Know whether your password can hold up.

Instant strength feedback and an optional breach check—without handing your password to us.

Check a password
LocalStrength analysis
ZeroPassword storage
5 charsSent for breach check

01 / Password checker

Your password stays on this device.

The meter reacts locally as you type. Nothing is submitted, stored, logged, or added to analytics.

Avoid typing a real password on a shared, monitored, or untrusted device.

Strength

Ready when you are

0/5

Type a password above. The strength check runs entirely in this browser.

Next moveStart with length: aim for 14 characters or more.

Rough crack-time estimateNot enough data
Length0 characters
Checks passed0 of 6
At least 14 characters
Better: 20+ characters
Upper and lowercase letters
Includes a number or symbol
No obvious sequence
No common password word
Optional breach lookup

Has this password appeared in known breach data?

We hash it here and send only the first five SHA-1 characters to Have I Been Pwned. The full password and full hash never leave.

Enter a password to enable the breach check.

02 / How it works

Privacy isn’t a footnote.
It’s the architecture.

01

Analyze locally

Length, patterns, variety, and rough crack time are calculated in your browser.

02

Hash locally

If you choose the breach lookup, your browser creates a SHA-1 hash on this device.

03

Compare anonymously

Only a five-character prefix is sent. Matching suffixes are compared here and discarded.

What we never receive

Your passwordThe full hashYour resultYour email

03 / Password managers

A strong password only works if every account gets its own.

A password manager makes unique credentials practical. Our first editorial shortlist focuses on two established options for individuals, families, and businesses.

Read the comparison guide →
Broadest fit

1Password

A polished option for families and teams that want flexible vaults, passkeys, Watchtower alerts, and a dual-key security design.

  • Individuals, families, and business plans
  • Passkey storage and sharing
  • Watchtower security alerts
Simple rollout

NordPass

A streamlined option with XChaCha20-encrypted vaults, passkeys, password health tools, breach monitoring, and broad platform support.

  • Personal and business plans
  • Password Health and breach scanner
  • Windows, macOS, Linux, Android, and iOS

04 / Password security guides

Answers you can use before the next login.

Learn how to create and change passwords safely, choose a password manager, adopt passkeys, and respond to a breach.

Explore all guides →

05 / Safer starting point

Generate a memorable passphrase.

Four unrelated words plus a number, generated on this device with your browser’s cryptographic random number generator.

Your generated passphrase will appear here.

Treat generated passwords as sensitive. Save them directly to a trusted password manager.

The rules that matter

  1. Make it unique.One password per account.
  2. Make it long.Use 14+ characters; 20+ is better.
  3. Use a manager.Generate, store, and share safely.
  4. Turn on MFA.Prefer passkeys or an authenticator app.

06 / Questions

Clear answers,
no scare tactics.

Does my password leave this browser?

No. Strength analysis is local. The optional breach lookup sends only a five-character hash prefix to the Pwned Passwords range API.

Is the crack-time estimate exact?

No. It is a teaching estimate. Actual time depends on hash type, hardware, rate limits, dictionary matches, and many other factors.

Does “not found” mean a password is safe?

No. It only means the password was not found in that data set. It must still be long, unique, and protected with MFA.

Why use SHA-1?

Only because the Pwned Passwords range service indexes passwords by SHA-1. SHA-1 is not recommended for storing passwords, and this site stores nothing.