> password check
Check a password
Type in a password and see how fast it could be guessed, and why. The estimate runs entirely in this browser, none of it goes online.
Stays in this browser. It goes nowhere, not into the address bar, not into a history and not into the statistics of this site.
Time to guess it
“Online, with lockout” means: at most 100 attempts per hour, as most sign-in pages enforce. “Offline, fast hash” is the worst case: someone has stolen a copy of the (poorly secured) password database and tries 10 billion guesses per second. A good storage method (bcrypt, Argon2) slows down exactly this case by orders of magnitude. You cannot tell from the outside, you can only hope.
Patterns found
What would make the password stronger
Rather have one rolled for you? Password generator
Calculates only in this browser. The password is not stored, not counted and not sent.
How it works
- 01Type in a password. The estimate appears after a short pause in typing.
- 02The tool splits the password into pieces and looks for the simplest explanation for each piece: a common password, a dictionary word (also with 4 instead of a or a capital first letter), a keyboard run like asdf (on a German QWERTZ keyboard), a sequence like 1234, a repetition, a year or a date (day before month, as in 25.12.1990). Whatever is left counts as true randomness.
- 03The cheapest way of splitting gives the number of guesses, and from that the time in the three scenarios.
Where the lists come from. The common passwords are compiled from well-known lists of common passwords (German and English). The dictionary words come from the same list of 1,224 German words as the passphrases of the generator, plus a small list of 549 everyday English words. So this check knows German better than English: an English word that is not on the small list counts as random characters here, and a date with the month first (12/25/1990) is not recognized as a date. In both cases the password comes out stronger than it may really be.
This is an estimate, not proof. A small method of its own, based on the idea of zxcvbn: no library, no complete dictionaries. A clever, unusual pattern that is not recognized here is treated as pure randomness and therefore rated stronger than it may really be. The other way round: what is marked as weak here really is weak.
Passphrases. Several real words, separated by spaces or hyphens (as in a passphrase), are rated word by word, not as one long string of characters. The separators themselves hardly count, and that is honestly included in the calculation.