Password Strength Checker
Inspect a local score and common password patterns
Enter a password first to inspect a heuristic score, composition model, and weak spots immediately; improvement advice and comparisons are available in Advanced mode.
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
This checker combines Unicode code-point length, character variety, and a small set of common-word, sequence and repetition rules into a heuristic score. It does not use a breach database or a comprehensive guessing model. For printable ASCII, the displayed composition bits assume independent uniform random selection from the detected character classes; they are not the entropy of a user-chosen password. Non-ASCII inputs receive no composition-bit estimate. Passwords are evaluated locally without saved drafts; use unique randomly generated passwords or passphrases and a password manager rather than optimizing solely for this score.
Production Snippets
Repeated emoji are eight code points, not sixteen
text
Input: 😀😀😀😀😀😀😀😀
Unicode code points: 8
Repeated-character run: detected
Composition-bit estimate: not available for non-ASCII
A heuristic score is not measured password entropy.Suggested Workflow
Frequently Asked Questions
Does a high score prove a password is safe?
No. Reused, leaked or predictable passwords can still score highly. The labels describe these local rules, not resistance to real attackers.
Is the displayed bit count actual entropy?
No. Length × log2(character-pool size) is a composition model under a uniform independent-random assumption. Human choices generally do not satisfy that assumption.
How are emoji and non-ASCII characters counted?
Length and repeated-character checks use Unicode code points consistently. A visual grapheme can contain several code points. No character-pool bit estimate is made for non-ASCII input.
Does this check leaked passwords?
No. It only checks local patterns and does not send the password to any breach lookup service.
How should passwords be stored by an application?
Use a dedicated salted password hash such as Argon2id, bcrypt or scrypt with appropriate parameters. Client-side strength scoring does not replace backend hashing, MFA or rate limits.
Keep browsing