What we found in your password
- Type a password above to analyse it.
We found no known pattern, so this figure is a ceiling: it holds if your password really is random. If you thought it up yourself, it is most likely a good deal less.
Brute force is estimated at 1012 guesses per second, the order of magnitude of an offline attack against a fast hash — the same model the generator uses. Against a slow hash (bcrypt, Argon2) the figure rises by many orders of magnitude.
How this works, and what it cannot know
We look your password up in dictionaries of leaked passwords, words, first names, surnames, cities, dates and keyboard walks, and we recognise common tricks like writing backwards or swapping a for @. We use zxcvbn-ts, open source, running entirely in your browser.
What we cannot know: if we find a pattern, the figure is reliable — that pattern is the shortcut an attacker would take. If we find none, the figure is only a ceiling: it means we don’t know your pattern, not that there isn’t one.
That is why the only exact figure on this site is in the generator: there the machine creates the password at random, so we know exactly how many combinations exist. Here we can only estimate.
We never send your password anywhere and we never store it. The only thing travelling over the network is the analyser, downloaded when you start typing.
How to read the ranking
The verdict comes from how long it would take to break your password, not from a sum of points for character variety. «Very weak» means under a second against an offline attack; «Very strong», more than a hundred thousand years. Even so, never reuse a password and lean on a proper manager.
Mix your characters and avoid predictable patterns (1234, qwerty, personal dates). If warnings come up in orange, read them: they point at what actually weakens your key.