6,895 tools, each one opened, scored and signed by a Toolio reviewer

Free tools / Password strength

Password strength tester

An entropy estimate and the time a fast offline attack would need. The password never leaves this page.

StrengthNothing yet
Entropy0 bits
Offline attack at ten billion guesses a second—
  • 12 or more characters
  • Lowercase letter
  • Uppercase letter
  • Number
  • Symbol
  • No common word or run

Entropy is a count of how many guesses a password could take, expressed in bits: each extra bit doubles the work. It comes from the length and the size of the character set, minus a penalty for the things attackers try first: dictionary words, keyboard runs, repeated characters and years. The crack time assumes an attacker with the hashed password and fast hardware, not someone typing at a login form.

Length beats cleverness. Four unrelated words are stronger than a short word with a number and a symbol bolted on, and far easier to remember. Better still, let a password manager generate and keep them, and spend your memory on the one that unlocks it.