SwiftTools

Password strength checker

Type a password to see its strength, character mix, and entropy — privately.

Test a password
Estimated strength—

How the password strength checker works

Type any password and the meter updates live. Strength is estimated from entropy — length multiplied by the size of the character pool you actually used (lowercase, uppercase, digits, symbols). Each extra bit of entropy doubles the guessing effort, which is why a long simple password usually beats a short complex one.

As a rule of thumb: under 36 bits is weak, 36–59 bits is fair, 60–79 is strong, and 80+ is very strong. The breakdown shows exactly which character types you’re using, so you can see what’s missing.

This is an estimate, not a guarantee — common words and predictable patterns (“Password123!”) are weaker than their entropy suggests. Never reuse one password across accounts.

Password strength checker FAQ

Is my password sent anywhere?

No — everything runs in your browser. The password you type is never uploaded, stored, logged, or transmitted in any form.

What is entropy?

A measure of unpredictability in bits. It is calculated as password length × log₂ of the character-pool size. Each additional bit doubles the number of guesses an attacker would need in a brute-force attempt.

What counts as a strong password?

Aim for 60+ bits of entropy as a solid baseline and 80+ for important accounts. In practice that means long and unique — length contributes more than exotic symbols.

Should I test my real passwords here?

Technically it is safe, since nothing leaves the page. As a habit, though, test passwords that are similar — not identical — to the ones you actually use.