Password Checker and Random Password Generator
Type a password to see how many guesses it might take, as a low and a high end with the assumptions stated, and which habits give it away. The generator makes a random password or a passphrase. Nothing you type is sent or stored.
What it measures
A password is cracked by guessing. This tool estimates how many guesses a password might take. It gives two numbers because nobody outside an attacker knows what the attacker knows. The high end is a blind search of every combination of the kinds of character used, which is what a random password of that length would need. The low end is an attacker who knows how people build passwords: common passwords, names, words, years, dates, mobile-number shapes, keyboard runs, counting and repeats.
How to use it
- Type or paste a password into the box. It starts on an invented example, and your first keystroke hides what you type.
- Read the rating, the two numbers and the table that turns them into time for four kinds of attacker.
- Read Why: it lists each habit it found in your password.
- Use the generator below if you want a random one instead.
The example buttons show how a very common password, a game’s name, a keyboard run, four unrelated words and twelve random characters each rate, so you can see the difference before you try your own shape.
A worked example
The invented password “Priya@2001” is a name, a symbol and a year, a shape many people use. The checker finds a common name and a year. An attacker who knows those habits needs about 18.7 million guesses; one who tries every combination blindly needs about 6.0 × 10¹⁹. A stolen password file stored the fast way is attacked at about 10 billion guesses a second, so the low end falls in less than a second. The rating is Very weak.
Compare “xK9#mQ2$vL7!”, twelve random characters in four kinds. Its low end is about 1.7 × 10²³ guesses and its high end 5.4 × 10²³, almost the same, because no pattern lowers it. At the same speed that is about 528 thousand years. Four unrelated words, “tiger-lamp-river-stone”, sit in between at 5.6 × 10¹⁷ guesses, about 2 years against the fast attack, which rates Good.
The assumptions
The page holds 200 common passwords, about 1,500 names and words, a short list of words tied to games and platforms, and rules for years, dates, keyboard runs, counting and repeats. A run of letters it does not know but that is shaped like a word is costed as one of 100,000 ordinary words. Each extra piece doubles the work. The four speeds are round figures, from about 100 guesses an hour for a site that slows guessers down to 10 billion a second for a stolen file stored the fast way. How a site stores your password decides which row applies, and you cannot see that. The rating follows the last row.
Making a password
The generator uses your browser’s secure random numbers (crypto.getRandomValues), and the password is shown only on this page. In random-character mode, sixteen characters from 68 possible ones, with every kind you tick present, carry about 97 bits. In words mode, each word from the 1,024-word list adds 10 bits, so six words and a two-digit number carry about 67 bits, which rates Good. The bits are the cautious reading: they assume the attacker knows the method and the list, which are public. Length does more than cleverness. Four more random characters from the same 68 multiply the work by about 21 million, which is why twelve random characters rate Strong and a clever-looking ten built on a name do not.
What it cannot tell you
It cannot see how any site stores or limits passwords. At the time of writing (8 October 2026), the platform’s sign-up form asks you to set a password and type it twice, and it may apply rules we have not seen. A strong password does not help if you give it away, so never send one or a code to anyone who messages you; the scam message checker shows what those requests look like. If you have forgotten a password, reset it from the login page. The register guide covers sign-up. See all the free tools.
Common questions
Is it a good idea to type my real password into a checker?
Only if you can trust the page, and you cannot easily check that. This page runs in your browser and sends nothing, but a different page might. Test a look-alike built the same way instead: another name, another year, the same symbol.
What do the low end and the high end of the estimate mean?
The high end is the work needed to try every combination of the kinds of character used, which is how strong a truly random password of that length would be. The low end is the work for an attacker who knows common habits. The nearer the two are, the less pattern there is.
Where does the list of 200 common passwords come from?
We put it together by hand for this page, from passwords that are widely reported as common and some habits that are common in India, such as gods’ names, cricketers and cities. It is short on purpose. It catches the worst, and attackers use lists millions long.
Is a passphrase of words better than random characters?
Both work, if they are chosen at random. A random 16-character password carries about 97 bits and a six-word passphrase with a number about 67. Words are easier to type and remember, and each extra word adds 10 bits. Words you pick yourself are far weaker than words the generator picks.
Can I use one strong password on every site?
No. When a site is breached, attackers try the leaked password on other sites. Use a different password for each account and keep them in a password manager, so you only have to remember one strong phrase.
Why does a typed word I know is common come out as a ‘word-shaped run’?
The page holds about 1,500 names and words. A run of letters that is not on its lists but is shaped like a word is still treated as one of 100,000 ordinary words, because real attackers hold far longer lists. It is a guess about their lists, and it keeps a pattern from looking stronger than it is.