PCHK

Password Strength Checker

Inspect a local score and common password patterns

Password Security
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
Options
Password input

Enter a password first to inspect a heuristic score, composition model, and weak spots immediately; improvement advice and comparisons are available in Advanced mode.

Heuristic assessment
The assessment will appear here
🔒 Local processing; passwords are not saved
Page reading mode

The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.

About this tool

This checker combines Unicode code-point length, character variety, and a small set of common-word, sequence and repetition rules into a heuristic score. It does not use a breach database or a comprehensive guessing model. For printable ASCII, the displayed composition bits assume independent uniform random selection from the detected character classes; they are not the entropy of a user-chosen password. Non-ASCII inputs receive no composition-bit estimate. Passwords are evaluated locally without saved drafts; use unique randomly generated passwords or passphrases and a password manager rather than optimizing solely for this score.

Production Snippets

Repeated emoji are eight code points, not sixteen

text

Input: 😀😀😀😀😀😀😀😀
Unicode code points: 8
Repeated-character run: detected
Composition-bit estimate: not available for non-ASCII
A heuristic score is not measured password entropy.

Suggested Workflow

Frequently Asked Questions

Does a high score prove a password is safe?

No. Reused, leaked or predictable passwords can still score highly. The labels describe these local rules, not resistance to real attackers.

Is the displayed bit count actual entropy?

No. Length × log2(character-pool size) is a composition model under a uniform independent-random assumption. Human choices generally do not satisfy that assumption.

How are emoji and non-ASCII characters counted?

Length and repeated-character checks use Unicode code points consistently. A visual grapheme can contain several code points. No character-pool bit estimate is made for non-ASCII input.

Does this check leaked passwords?

No. It only checks local patterns and does not send the password to any breach lookup service.

How should passwords be stored by an application?

Use a dedicated salted password hash such as Argon2id, bcrypt or scrypt with appropriate parameters. Client-side strength scoring does not replace backend hashing, MFA or rate limits.

Keep browsing