Strength checkers estimate how much effort it would take to guess a password. They are useful as feedback while choosing one, but they measure structure rather than secrecy — and the distinction matters.
How to use the Password Strength Meter
- Type or paste a password to test
- Review the strength score and which criteria it meets
- Lengthen it or remove predictable patterns if it scores poorly
- Check it against a breach database before using it anywhere
What the score is actually measuring
The assessment looks at length, the range of character types used, and whether the password contains obvious patterns — dictionary words, sequences like 1234 or qwerty, repeated characters, and the predictable substitutions (@ for a, 0 for o) that attackers' rule sets expand automatically.
What it cannot see is the one thing that matters most: whether the password has already been exposed in a breach. A password that appears in a leaked credential dump is worthless however complex it looks, because attackers try known passwords first. Check against Have I Been Pwned for that — it uses k-anonymity, so you never send the full password.
Why a strong password can still be the wrong one
Three failure modes that a strength meter cannot detect:
Reuse. A 20-character random password used on five sites is as weak as the least secure of those sites. Credential stuffing does the rest.
Phishing. Password strength is irrelevant if you type it into a convincing fake login page. This is why phishing-resistant second factors — passkeys, hardware keys — matter more than password complexity.
Storage. If a service stores passwords badly, yours is exposed regardless of how strong it was. You cannot control this, which is another argument for unique passwords everywhere.
In practice: a password manager generating unique random passwords, plus two-factor authentication, does far more than optimising any single password's score.
Frequently asked questions
Is it safe to type my real password here?
The check runs entirely in your browser and nothing is transmitted. As a general habit though, avoid entering live passwords into any website — test a variation of similar structure instead.
My password scored strong. Is it safe?
Only structurally. The checker cannot know whether it has appeared in a breach, whether you have reused it, or whether the service storing it does so properly. Strong structure is necessary, not sufficient.
Does adding a number and symbol make a password strong?
Much less than people assume. P@ssw0rd1 satisfies most complexity rules and is cracked instantly, because the substitutions are in every attacker's rule set. Length and unpredictability matter far more.
What is entropy?
A measure of unpredictability in bits — effectively how many guesses an attacker needs. Each bit doubles that number. Under 50 bits is weak, 80 is reasonable, over 100 is strong.