How strong is this password?

Get a strength estimate and find out whether the password has already leaked in a data breach. The password itself never leaves your browser.

k-anonymity: only the first 5 characters of the password's SHA-1 hash are sent to Have I Been Pwned; it returns hundreds of possible matches and the comparison happens on your device. Nothing is stored.

Need a new one? Generate a passphrase

Four or five random words are easier to type on a phone and stronger than “Summer2024!”. Generated on your device with a cryptographic random source.

Prefer random characters?

How the password checker works

  1. Type a password

    It stays in your browser. We estimate strength from length, character variety and known patterns such as "Word2024!".

  2. We check it against leaked passwords privately

    Only the first five characters of its SHA-1 hash go to Have I Been Pwned; several hundred candidates come back and the match happens on your device.

  3. Generate a better one

    Four or five random words are stronger than most "complex" passwords and far easier to type on a phone.

Questions people ask

Is it safe to type a real password here?

The password never leaves your browser and nothing is stored. Even so, we suggest testing a candidate rather than a password you rely on, and changing any password that shows as leaked.

Why are long passphrases better than symbols?

Attackers guess billions of combinations per second; every extra character multiplies the work far more than swapping an "a" for "@". Length and randomness win.

How many times is "too many" for a leaked password?

Once. If a password appears in any breach it is in every cracking list.

Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.