Password Strength Checker

Check password strength, entropy, and estimated crack time. Get suggestions for stronger passwords.

By Konstantin Iakovlev · Updated September 2026 · Source: NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (August 2025)

Use the Password Strength Checker above to calculate your results. Enter your values and see instant results — all calculations run in your browser.

Disclaimer: This calculator is for informational purposes only. Results are estimates based on the information you provide and the assumptions described on this page.

How It Works

Our Password Strength Checker analyzes your password's robustness by evaluating its entropy, a measure of randomness and unpredictability. A password built from a common word or pattern can fall to a dictionary attack almost at once. This tool gives an entropy score, a strength rating, two brute-force crack-time estimates and suggestions for improving the password.

The score starts as length × log2(pool), where the pool adds 26 for lowercase, 26 for uppercase, 10 for digits and 33 for symbols, counting only the sets the password uses. It is halved if the password contains a common pattern such as "password", "qwerty" or "123456", multiplied by 0.8 for three identical characters in a row and by 0.8 again for a run such as "123" or "abc". The rating steps up at 28, 36, 60, 80 and 100 bits, from Very Weak to Very Strong. The two crack-time rows take half of 2^score guesses, so the pattern penalties count, at 10 billion and 100 billion guesses per second. Those are speeds for an attacker who has stolen a password database and guesses offline; a live login page that limits failed attempts is far slower to attack.

Many users make the mistake of reusing passwords or using easily guessable combinations like birthdays or common dictionary words. Avoid sequential patterns, keyboard patterns, and personal information that can be found online. Length counts for more than variety: in this checker, 16 random lowercase letters score 75.2 bits, more than 10 characters drawn from all four sets (65.7 bits).

Example: Evaluating a Common Password

  1. 1 Input: the password 'Password123!'.
  2. 2 Pool: it uses uppercase, lowercase, digits and a symbol, so 26 + 26 + 10 + 33 = 95. Starting score: 12 characters × log2(95) = 12 × 6.570 = 78.8 bits.
  3. 3 Penalties: it contains the common pattern 'password', which halves the score to 39.4 bits, and the run '123', which multiplies it by 0.8: 31.5 bits, rated Weak. The suggestions are to avoid common words and patterns and to avoid sequential characters.
  4. 4 The crack-time rows use that penalized score: 2^31.5 is about 3.1 billion guesses, and half of them take about 0.16 seconds at 10 billion guesses per second, so both rows read Instantly. Counting all 95^12 combinations instead would suggest 857,000 years, but real attacks try dictionary words with digits and symbols appended long before brute force, which is what the penalties stand for.

Frequently Asked Questions

What makes a strong password?
A strong password is long and random. NIST SP 800-63B-4 (August 2025) sets a 15-character minimum for a password used as the only sign-in factor and tells services not to require mixes of character types. Better yet, use a passphrase of 4-5 random words (e.g., "correct horse battery staple") for both length and memorability.
How long would it take to crack my password?
At this checker's brute-force rates (half of all combinations at 10 billion or 100 billion guesses per second), a random 8-character password using all four character sets takes 9 hours to 4 days, a 12-character one 86,000 to 857,000 years, and a 16-character one trillions of years. Those figures assume random characters; a password built on a dictionary word falls far sooner.
Should I use a password manager?
Yes. A password manager generates and stores unique, strong passwords for every account. You only need to remember one master password. This is far more secure than reusing passwords or using simple variations across sites.