Skip to content

Free Tools/Password Strength

How fast could your password be cracked?

Test a password's real strength, then generate a passphrase that's both stronger and easier to remember. Everything runs on your device; nothing you type here is ever sent anywhere.

Test a password

Analyzed on your device only. Nothing is sent or stored.

Generate a passphrase

Picked at random from 2,848 short English words (based on the EFF wordlist) using your browser's cryptographic random number generator. We never see what's generated.

Why length beats complexity

For years, everyone was taught the same recipe: 8 characters, a capital letter, a number, a symbol. Attackers know the recipe too. Cracking tools try "P@ssw0rd1!" and its millions of cousins first, because that's how humans actually fill in those requirements.

The math favors a different approach. Each extra character multiplies the work an attacker has to do, so a 20-character phrase of ordinary words is astronomically harder to crack than a cryptic 8-character password. That's why security agencies like NIST and CISA now recommend long passphrases: something like "gravy-shrug-oval-tulip-crank" is stronger than "X7#kQ2!p" and you can actually remember it.

The best setup for a business: a password manager that generates and remembers a unique password for every account, protected by one strong passphrase you memorize, with multi-factor authentication on anything important. We help companies roll that out in a week.

Common questions

Is it safe to type a real password here?

This tool runs entirely on your device. The password is analyzed by code already loaded in your browser and is never transmitted, logged, or stored. You can even load the page, turn off your internet connection, and it still works. That said, the safest habit for your most sensitive passwords is simple: never type them anywhere except the site or app they belong to.

Why do you recommend passphrases over complex passwords?

Length beats complexity. "Tr0ub4dor!" feels strong but is short and follows predictable substitution patterns that cracking tools try first. Four to six random words are far harder to crack and far easier to remember. The catch is the words must be truly random, picked by a generator, not by you. Human-chosen phrases like song lyrics are much weaker.

What do the crack-time estimates assume?

Two scenarios. "Online" assumes an attacker guessing against a login page at about 100 guesses per second. "Offline" assumes they've stolen a password database and are running a modern cracking rig at about 100 billion guesses per second. Real-world speeds vary a lot with how a site stores passwords, so treat these as ballpark comparisons, not guarantees.

Do I really need a different password for every account?

Yes, and it's the single biggest upgrade most people can make. When one site is breached, attackers immediately try that email and password everywhere else. A password manager makes unique passwords practical: you remember one strong passphrase, it remembers the rest.

Passwords are step one. Want the rest handled?

Password managers, multi-factor authentication, breach monitoring, and staff training: we set all of it up as part of our managed plans. Start with a free assessment.