Skip to content
Passwordify
Strength analyzer

How strong is your password?

Real strength estimation with the zxcvbn engine — entropy, crack-time and concrete feedback, plus a breach lookup. Nothing leaves your browser.

Awaiting input
Guesses to crack
—
Offline crack time
—

Runs entirely in your browser. The breach check sends only the first 5 characters of a SHA-1 hash.

How it works

Guesses, not character classes.

Most strength meters count how many character types you used and call it a day. That's why they're fooled by predictable passwords. Passwordify uses zxcvbn — the same estimator Dropbox open-sourced — which scores a password by how many guesses a real attacker would need.

It recognizes dictionary words, names, dates, keyboard walks (qwerty), repeats and leetspeak substitutions, then reports the weakest pattern it found. The score you see maps directly to an estimated crack time.

Generate a strong one instead
0 · Very weak
Instantly guessable — in the top breached passwords.
1 · Weak
Falls in minutes to hours against an offline attack.
2 · Fair
Okay for low-stakes accounts, not for anything important.
3 · Strong
Resists offline attacks for a long time.
4 · Very strong
Impractical to crack with today's hardware.

Questions

What makes a password strong?

Length and unpredictability — not symbols. A long passphrase of random words beats a short “P@ssw0rd!”. Strength is about how many guesses an attacker needs, which is what this tool estimates.

Why does “P@ssw0rd!” score badly?

Because attackers know every common substitution. zxcvbn models real cracking: dictionaries, leetspeak, keyboard walks and repeats. A rule-based meter that just counts character classes would wrongly call it strong.

Is my password sent anywhere?

No. Strength analysis runs entirely in your browser. The optional breach check sends only the first five characters of a SHA-1 hash — never the password itself.

Ship this check in your own app

One API call scores any password with the same engine.