Get a strength estimate and find out whether the password has already leaked in a data breach. The password itself never leaves your browser.
Four or five random words are easier to type on a phone and stronger than “Summer2024!”. Generated on your device with a cryptographic random source.
It stays in your browser. We estimate strength from length, character variety and known patterns such as "Word2024!".
Only the first five characters of its SHA-1 hash go to Have I Been Pwned; several hundred candidates come back and the match happens on your device.
Four or five random words are stronger than most "complex" passwords and far easier to type on a phone.
The password never leaves your browser and nothing is stored. Even so, we suggest testing a candidate rather than a password you rely on, and changing any password that shows as leaked.
Attackers guess billions of combinations per second; every extra character multiplies the work far more than swapping an "a" for "@". Length and randomness win.
Once. If a password appears in any breach it is in every cracking list.
Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.