Password Strength Calculator
Check your password's entropy (in bits) and estimated brute-force crack time. All calculation happens instantly in your browser - your password is never sent anywhere or stored.
Enter a Password to Test
Entropy Formula
Password Entropy
= Password Length × log₂(Character Pool Size)
Character Pool Sizes
+ Uppercase letters: 52
+ Numbers: 62
+ Symbols: ~94 (full printable ASCII)
Worked Example
Pool size = 94
Entropy = 10 × log₂(94) ≈ 10 × 6.55 ≈ 65.5 bits
At 10 billion guesses/second, crack time ≈ 65.5 bits ÷ practical brute force ≈ many years
Entropy Strength Scale
28-35 bits: Weak
36-59 bits: Reasonable
60-127 bits: Strong
128+ bits: Very Strong
Try These Examples
Frequently Asked Questions
Password Strength Calculator - Understanding Entropy and Real Security
Password strength isn't just a feeling - it can be measured mathematically using a concept called entropy, expressed in bits, which quantifies exactly how many attempts a brute-force attack would need to guess a password on average. This calculator computes your password's entropy and translates it into an estimated crack time and strength rating, all calculated instantly in your browser without ever transmitting or storing what you type.
Why Entropy Is a Better Measure Than "Strength Rules"
Many websites enforce arbitrary rules like "must contain one uppercase letter, one number, and one symbol," but these rules don't necessarily correlate with real security. Entropy gets at the actual mathematical question that matters: how many possible combinations exist, and therefore how long would a brute-force attack take on average to find the right one? A password can technically satisfy every complexity rule and still be weak (like "Passw0rd!") if it's predictable, while a password that breaks every rule (like a long string of random lowercase words) can have very high entropy simply due to its length.
Length Matters More Than Complexity
Because entropy grows with the exponent of password length, adding characters increases security far more dramatically than adding character variety. Doubling a password's character pool (say, from lowercase-only to lowercase+uppercase) increases entropy per character only modestly, but adding just a few more characters to the password length can add significantly more entropy overall. This is the core insight behind the "long passphrase" approach to password security, popularized by the idea that a memorable phrase like "correct horse battery staple" can be dramatically more secure than a short, complex-looking password like "Tr0ub4dor&3", despite looking less "complicated" at a glance.
The Gap Between Theoretical Entropy and Real-World Security
It's important to understand what this calculator measures and what it doesn't. The entropy calculation assumes a pure brute-force attack that tries every possible combination with equal likelihood. Real attackers, however, are smarter than that: they use dictionaries of common passwords, leaked password databases, and pattern recognition that tries likely variations (like capitalizing the first letter, adding "123" or "!" at the end, or substituting "o" with "0") before resorting to true brute force. This means a password like "password123!" might show reasonable calculated entropy but would actually be cracked almost instantly by real attackers, because it follows an extremely common pattern that's near the top of every cracking dictionary.
Practical Guidelines for Strong Passwords
- Prioritize length over complexity - aim for at least 12-16 characters, ideally more for important accounts.
- Avoid dictionary words, names, and predictable patterns - even with substitutions like "P@ssw0rd," since these are well-known to password-cracking tools.
- Never reuse passwords across different accounts - a breach at one service shouldn't compromise your other accounts.
- Consider a passphrase of random, unrelated words - genuinely random word combinations (not a common phrase or song lyric) can be both memorable and high-entropy.
- Use a password manager to generate and store unique, high-entropy passwords for every account, removing the need to memorize dozens of different complex passwords.
A Note on Privacy
This calculator performs all entropy calculations directly in your browser using JavaScript - your password is never sent to any server, logged, or stored anywhere. That said, as a general security habit, it's wise to avoid typing your actual real-world passwords into any third-party tool, even one that claims to compute locally; testing with a similar but not identical password is a reasonable precaution.
How this calculator works, and where the numbers come from
The Password Strength Checker applies the standard formula for this calculation to the values you enter and updates the result as you type. The calculation itself happens in your browser, and the page explains the method so you can check any result by hand.
Please note: Results are provided for general information and are calculated from the values you enter.