How strong is your password?
Real strength estimation with the zxcvbn engine — entropy, crack-time and concrete feedback, plus a breach lookup. Nothing leaves your browser.
Runs entirely in your browser. The breach check sends only the first 5 characters of a SHA-1 hash.
Guesses, not character classes.
Most strength meters count how many character types you used and call it a day. That's why they're fooled by predictable passwords. Passwordify uses zxcvbn — the same estimator Dropbox open-sourced — which scores a password by how many guesses a real attacker would need.
It recognizes dictionary words, names, dates, keyboard walks (qwerty), repeats and leetspeak substitutions, then reports the weakest pattern it found. The score you see maps directly to an estimated crack time.
Generate a strong one insteadQuestions
What makes a password strong?
Length and unpredictability — not symbols. A long passphrase of random words beats a short “P@ssw0rd!”. Strength is about how many guesses an attacker needs, which is what this tool estimates.
Why does “P@ssw0rd!” score badly?
Because attackers know every common substitution. zxcvbn models real cracking: dictionaries, leetspeak, keyboard walks and repeats. A rule-based meter that just counts character classes would wrongly call it strong.
Is my password sent anywhere?
No. Strength analysis runs entirely in your browser. The optional breach check sends only the first five characters of a SHA-1 hash — never the password itself.
Ship this check in your own app
One API call scores any password with the same engine.