Password Strength Checker

Find out how quickly a password could be cracked, and whether it has leaked in a data breach.

Strength is checked on your device. The breach check sends only the first 5 characters of the password's SHA-1 hash to Have I Been Pwned, never the password itself.

How strength is measured

This uses zxcvbn, which looks for dictionary words, names, keyboard patterns (qwerty), dates and common substitutions (p@ssw0rd), not just character rules. That's why "Password@123" scores badly despite having symbols.

Private breach check

The password is hashed on your device with SHA-1, and only the first 5 characters of that hash are sent to Have I Been Pwned. The service returns every leaked hash with that prefix, and the match is checked on your device. Your password never leaves it.

Frequently asked questions

Is it safe to type my real password here?

Strength is checked locally and the breach check uses k-anonymity, as described above. For extra caution, test a similar password rather than your exact one.

What makes a strong password?

Length and unpredictability. Four or five random words, or 16+ random characters from a password manager, work well.

It says my password was breached. Now what?

Change it everywhere you've used it, and turn on two-factor authentication.

More text and developer tools

See all text and developer tools →