Enter a Password to Test

Calculated entirely in your browser. Nothing is transmitted or saved.
Enter a password above
Entropy
-
Est. Crack Time
-

Entropy Formula

Password Entropy

Entropy (bits) = log₂(Character Pool Size ^ Password Length)
= Password Length × log₂(Character Pool Size)

Character Pool Sizes

Lowercase letters only: 26
+ Uppercase letters: 52
+ Numbers: 62
+ Symbols: ~94 (full printable ASCII)

Worked Example

Password: "Tr0ub4dor!" (10 characters, all 4 character types)

Pool size = 94
Entropy = 10 × log₂(94) ≈ 10 × 6.55 ≈ 65.5 bits

At 10 billion guesses/second, crack time ≈ 65.5 bits ÷ practical brute force ≈ many years

Entropy Strength Scale

Below 28 bits: Very Weak
28-35 bits: Weak
36-59 bits: Reasonable
60-127 bits: Strong
128+ bits: Very Strong

Try These Examples

"password" (common word)
Very Weak - ~37.6 bits, but predictable
"Tr0ub4dor!" (mixed, 10 chars)
Strong - ~65.5 bits
"correcthorsebatterystaple" (long phrase)
Very Strong - ~122 bits
"X7$mK2!qP9@wZ" (random, 13 chars)
Very Strong - ~85.2 bits

Frequently Asked Questions

Password entropy, measured in bits, quantifies how unpredictable a password is - specifically, how many attempts a brute-force attack would need on average to guess it. Each additional bit of entropy doubles the number of possible combinations, so entropy is a mathematically grounded way to compare password strength, rather than relying on vague labels like "weak" or "strong."
Adding character variety generally increases entropy because it expands the pool of possible characters an attacker must consider, but length matters more than complexity in most cases. A long password using only lowercase letters (like a random 20-character phrase) can have more entropy than a short, complex one (like an 8-character password with symbols), because entropy grows exponentially with length.
This tool estimates theoretical entropy against a pure brute-force attack, but real-world attacks often use smarter methods - dictionary attacks, common password lists, and pattern recognition (like "Password123!" or keyboard patterns) can crack passwords far faster than brute-force math suggests, even if the entropy calculation looks reasonably high. Avoiding common words, patterns, and personal information matters as much as raw entropy.
As a general guideline, below 28 bits is considered very weak, 28-35 bits weak, 36-59 bits reasonable, 60-127 bits strong, and 128+ bits very strong. For important accounts, security experts generally recommend passwords with at least 60 bits of entropy, achieved most easily through length (12+ characters) combined with reasonable character variety.
Yes, for most people. Password managers can generate and store long, high-entropy, unique passwords for every account without requiring you to memorize them, eliminating the common tradeoff between security and memorability. Using a password manager with a single strong master password is widely recommended by security professionals over trying to remember many different strong passwords manually.

Password Strength Calculator - Understanding Entropy and Real Security

Password strength isn't just a feeling - it can be measured mathematically using a concept called entropy, expressed in bits, which quantifies exactly how many attempts a brute-force attack would need to guess a password on average. This calculator computes your password's entropy and translates it into an estimated crack time and strength rating, all calculated instantly in your browser without ever transmitting or storing what you type.

Quick reference: Entropy (bits) = Password Length × log₂(Character Pool Size). Higher entropy means exponentially more possible combinations an attacker must try.

Why Entropy Is a Better Measure Than "Strength Rules"

Many websites enforce arbitrary rules like "must contain one uppercase letter, one number, and one symbol," but these rules don't necessarily correlate with real security. Entropy gets at the actual mathematical question that matters: how many possible combinations exist, and therefore how long would a brute-force attack take on average to find the right one? A password can technically satisfy every complexity rule and still be weak (like "Passw0rd!") if it's predictable, while a password that breaks every rule (like a long string of random lowercase words) can have very high entropy simply due to its length.

Length Matters More Than Complexity

Because entropy grows with the exponent of password length, adding characters increases security far more dramatically than adding character variety. Doubling a password's character pool (say, from lowercase-only to lowercase+uppercase) increases entropy per character only modestly, but adding just a few more characters to the password length can add significantly more entropy overall. This is the core insight behind the "long passphrase" approach to password security, popularized by the idea that a memorable phrase like "correct horse battery staple" can be dramatically more secure than a short, complex-looking password like "Tr0ub4dor&3", despite looking less "complicated" at a glance.

The Gap Between Theoretical Entropy and Real-World Security

It's important to understand what this calculator measures and what it doesn't. The entropy calculation assumes a pure brute-force attack that tries every possible combination with equal likelihood. Real attackers, however, are smarter than that: they use dictionaries of common passwords, leaked password databases, and pattern recognition that tries likely variations (like capitalizing the first letter, adding "123" or "!" at the end, or substituting "o" with "0") before resorting to true brute force. This means a password like "password123!" might show reasonable calculated entropy but would actually be cracked almost instantly by real attackers, because it follows an extremely common pattern that's near the top of every cracking dictionary.

Practical Guidelines for Strong Passwords

  • Prioritize length over complexity - aim for at least 12-16 characters, ideally more for important accounts.
  • Avoid dictionary words, names, and predictable patterns - even with substitutions like "P@ssw0rd," since these are well-known to password-cracking tools.
  • Never reuse passwords across different accounts - a breach at one service shouldn't compromise your other accounts.
  • Consider a passphrase of random, unrelated words - genuinely random word combinations (not a common phrase or song lyric) can be both memorable and high-entropy.
  • Use a password manager to generate and store unique, high-entropy passwords for every account, removing the need to memorize dozens of different complex passwords.

A Note on Privacy

This calculator performs all entropy calculations directly in your browser using JavaScript - your password is never sent to any server, logged, or stored anywhere. That said, as a general security habit, it's wise to avoid typing your actual real-world passwords into any third-party tool, even one that claims to compute locally; testing with a similar but not identical password is a reasonable precaution.

How this calculator works, and where the numbers come from

The Password Strength Checker applies the standard formula for this calculation to the values you enter and updates the result as you type. The calculation itself happens in your browser, and the page explains the method so you can check any result by hand.

Please note: Results are provided for general information and are calculated from the values you enter.

Sources and further reading

Last reviewed: by the CalcQube Editorial Team. See our editorial policy for how we build and check calculators, or report an error.