Password check
Password strength check: how secure is my password?
Typing your password into a random website to “check” it is not a great idea. The check in the Password Generator therefore runs entirely in your browser – the password is neither sent nor stored. Here is what it detects and how to read the result.
Type a password and instantly see which patterns an attacker would exploit – locally in your browser, nothing is transmitted.
Check a passwordThe short version
- In the Password Generator, switch to Check.
- Type the password – the result appears instantly.
- “Detected patterns” shows where an attacker would start.
- Replace anything below “Strong” with a randomly generated password.
Your password stays on your device. The check uses the open-source library zxcvbn with English and German dictionaries. It loads once and then runs entirely in your browser – even offline. The input field is not stored.
How the check works
Many “password strength” meters only count character types: a capital, a digit, a symbol – done. By that logic Password1! is strong. Real attackers work differently, and that is what the check simulates: it splits the password into pieces, finds the most likely explanation for each (word, name, date, pattern) and calculates how many guesses an attacker with a good strategy would need.
The number of guesses gives the time to crack – assuming an offline attack at 10 billion guesses per second, i.e. a stolen password database.
What the check detects
| Pattern | Example |
|---|---|
| Common passwords | letmein, password, iloveyou |
| English and German words | sunshine, dragon |
| First and last names | Michael, Smith |
| Years and dates | 1987, 12/24/1990 |
| Keyboard patterns | qwerty, asdf, 1qaz2wsx |
| Sequences and repeats | abcdef, 123456, aaaa |
| Common substitutions | P@ssw0rd (@ for a, 0 for o) |
| Reversed words | drowssap |
Try a few examples first, like “Summer2026!” or “qwerty123” – you’ll see how quickly made-up passwords fall.
Reading the result
| Rating | Meaning |
|---|---|
| Very weak / Weak | Cracked in seconds to days. Replace it now, especially if it is used more than once. |
| Fair | Withstands simple attacks, but not a stolen database. Not enough for important accounts. |
| Strong | Good – as long as the password is used for one account only. |
| Very strong | Practically impossible to guess. |
The ratings use the same scale as the generator (bits of entropy), so generated and checked passwords are comparable.
What the check can’t do
- Data breaches: a local check can’t know whether your password was stolen in a breach. Services like “Have I Been Pwned” do that; many password managers check automatically.
- Personal context: the check doesn’t know your dog’s name or your house number – an attacker targeting you might.
- Reuse: the strongest password doesn’t help if it was also used on a forum that got hacked.
My password is weak – now what?
- Generate a new password in the generator – at least 16 characters or a passphrase of 6 words.
- Change it on the affected service and save it in your password manager.
- Check where else the old password was used and change it there too – starting with your email account.
- Turn on two-factor authentication wherever possible.
Check your password
Detects words, names, years, keyboard patterns and common substitutions – and estimates the time to crack. Local in your browser, nothing is sent.
Frequently asked questions
Is it safe to check my password here?
Yes. The check runs entirely in your browser; the password is not sent, stored or logged. After loading, it even works offline.
How is the strength calculated?
With the open-source library zxcvbn: it detects words, names, dates and patterns and estimates the number of guesses an attacker would need, which gives the time to crack at 10 billion guesses per second.
Why is “Password123!” weak although it follows all the rules?
Because it consists of one of the most common words, a simple number sequence and a typical symbol at the end – exactly what attackers try first.
Does the check tell me if my password was leaked?
No. That would require querying an online service like Have I Been Pwned. Many password managers offer this check.
Does it detect German words too?
Yes. Besides English lists it includes German dictionaries, common German first and last names and keyboard patterns like “qwertz”.
What is a safe result?
“Strong” or “Very strong” – provided the password is used for a single account only.
Sources
- zxcvbn-ts – the open-source library behind the password check, based on Dropbox’s zxcvbn.
- NIST Special Publication 800-63B – Digital Identity Guidelines: Authentication, National Institute of Standards and Technology.