# password.es · Password strength checker

> We don’t count uppercase or symbols: we look your password up in dictionaries of words, names, cities and keyboard patterns, and estimate how many guesses it would really take.

password.es · Original: https://password.es/en/checker/

---

# Analyze your password in depth

We don’t count uppercase or symbols: we look your password up in dictionaries of words, names, cities and keyboard patterns, and estimate how many guesses it would really take.

All analysis happens in your browser. We never send information or store the results.

We hide the password by default. You can toggle visibility with the side button.

The verdict comes from the time, not from a percentage.

to break it by brute force

## What we found in your password

- Type a password above to analyse it.

We found no known pattern, so this figure is a **ceiling**: it holds if your password really is random. If you thought it up yourself, it is most likely a good deal less.

Brute force is estimated at **10^12 guesses per second**, the order of magnitude of an *offline* attack against a fast hash — the same model [the generator](https://password.es/) uses. Against a slow hash (`bcrypt`, `Argon2`) the figure rises by many orders of magnitude.

## How this works, and what it cannot know

We look your password up in dictionaries of leaked passwords, words, first names, surnames, cities, dates and keyboard walks, and we recognise common tricks like writing backwards or swapping `a` for `@`. We use [zxcvbn-ts](https://github.com/zxcvbn-ts/zxcvbn), open source, running entirely in your browser.

**What we cannot know:** if we find a pattern, the figure is reliable — that pattern is the shortcut an attacker would take. If we find none, the figure is only a **ceiling**: it means we don&rsquo;t know your pattern, not that there isn&rsquo;t one.

That is why the only exact figure on this site is in [the generator](https://password.es/): there the machine creates the password at random, so we know exactly how many combinations exist. Here we can only estimate.

We never send your password anywhere and we never store it. The only thing travelling over the network is the analyser, downloaded when you start typing.

## How to read the ranking

The verdict comes from how long it would take to break your password, not from a sum of points for character variety. «Very weak» means under a second against an offline attack; «Very strong», more than a hundred thousand years. Even so, never reuse a password and lean on a proper manager.

Mix your characters and avoid predictable patterns (1234, qwerty, personal dates). If warnings come up in orange, read them: they point at what actually weakens your key.

## Frequently asked questions

### Which algorithm does it use?

zxcvbn, the open-source library that looks your password up in dictionaries of words, names, cities, dates and keyboard patterns and estimates how many guesses it would take. We used to run PasswordMeter (2006), which counted character variety: it called `Password1!` very strong and a five-word random phrase very weak. Exactly backwards.

### Are my passwords stored?

Never. The calculation happens in your browser and we send nothing to the server. You can disconnect from the internet and it will keep working.

### What counts as a «good enough» password?

One that holds out long enough and appears in no dictionary. Aim for «Strong» or «Very strong», and for the findings list to come back empty: a pattern we found is a shortcut the attacker has too. Even then, pair it with a manager and two-factor authentication.

### What else do you recommend?

Besides the generator, read our guides on password.es to learn how to build memorable passwords and switch on extra measures such as managers or hardware keys.

### Why does the generator use 27 symbols when this page counts 33?

Because they measure different things. Here, if you type a symbol, we assume you could have typed any of the 33 on an ASCII keyboard: that is the alphabet an attacker would have to walk through. The generator uses 27 on purpose, leaving out quotes and slashes, which break passwords when you paste them into terminals, spreadsheets and config files. The six missing ones cost less than a third of a bit per character; a password that breaks when you copy it costs rather more.
