Password Strength & Breach Checker
Estimates entropy, detects weak patterns, and checks against the HaveIBeenPwned breach database. Aligned with NIST SP 800-63B guidance.
Privacy-first — your password never leaves this browser
—
—
Characters
—
Symbol pool
—
Bits entropy
Character Classes
Pattern Warnings
Estimated Crack Time
Average case — attacker tries half the keyspace
NIST SP 800-63B Checklist
Breach Database Check
Uses k-anonymity: only the first 5 hex characters of the SHA-1 hash are sent to HaveIBeenPwned. The full hash and your password remain in your browser.