UTL

Password Strength Checker

Type a password to see its strength, estimated entropy, and an approximate time to crack it offline.

    How it's calculated

    Entropy is estimated as length × log2(character pool size), where the pool size depends on which character types are present (lowercase, uppercase, digits, symbols). The crack-time estimate assumes an offline attack at 10 billion guesses per second — a realistic figure for a fast attack against a weakly-hashed password, though real-world numbers vary enormously depending on how a service actually stores passwords.

    This is a rough estimate, not a guarantee. It doesn't check against the billions of real leaked passwords attackers actually try first — a password can pass every rule here and still be one a dictionary attack finds instantly if it is a common word, name, or an only-slightly-modified well-known password.

    Frequently asked

    Is my password sent anywhere when I type it here?

    No — everything runs in your browser with JavaScript; nothing is transmitted or logged.

    Why did a password with good variety still score as weak?

    If a password matches a commonly used password exactly, it's scored as very weak regardless of its character mix, since real attackers try known-common passwords first — length and variety don't help if the whole password is already on every cracking wordlist.