Password strength estimator
Estimate resistance locally and explain model limitations.
How to use Password strength estimator
Password strength estimator rates a password you type with the zxcvbn library, which checks it against dictionaries and common patterns. It reports a score from 0 to 4, the estimated number of guesses, a crack-time estimate for offline attacks on a slow hash at 10,000 guesses per second, and any warnings or suggestions. It is educational and cannot detect reuse.
- Paste the source into the input editor, or load the built-in example.
- Check the source format before running the operation.
- Run password strength estimator, review the output, then use the available copy or download controls.
What this tool supports
Estimate resistance locally and explain model limitations. Assess supplied passwords locally rather than generate them.
Limits and processing
CSV/XLSX inputs are capped at 10 MB each, 200 columns and 20,000 rows; joined output is capped at 20,000 rows. JSONPath script/filter evaluation is disabled. Other operations apply their visible controls and text limits.
Example source
correct horse battery staple
Frequently asked questions
What does a password score of 0 to 4 mean?
It is a rough strength band derived from the estimated guess count: 0 is very easy to guess and 4 is the strongest band. Read it together with Estimated guesses, which gives the underlying number, rather than treating any score as proof a password is safe.
Why does my password with symbols still get a low score?
zxcvbn looks for dictionary words, names, keyboard patterns, dates, repeats and common substitutions. A password built from a common word with predictable changes can need few guesses despite its symbols; the Feedback line explains what was found.
Does the password strength estimator check if my password was leaked?
No. It estimates guessability from dictionaries and patterns only, with no lookup against breach lists. The tool also notes that it cannot detect password reuse or prove a password is safe, so treat the result as educational guidance.
Where is my input processed?
This operation processes its source in your browser. Copy and download are explicit actions; source input is not saved in an account or history.
What are the input limits?
CSV/XLSX inputs are capped at 10 MB each, 200 columns and 20,000 rows; joined output is capped at 20,000 rows. JSONPath script/filter evaluation is disabled. Other operations apply their visible controls and text limits.