Tools · Strength Checker

How strong is your password?

Type a password to see its strength, entropy in bits, and how long it would take to crack. Everything runs on your device — nothing is sent anywhere.

—
a–z A–Z 0–9 !@#$

    Analyzed locally in your browser. No network, no logging, no telemetry.

    What actually makes a password strong?

    Entropy · Length · Unpredictability

    Entropy, not complexity rules

    Forced “1 uppercase, 1 number, 1 symbol” rules push people toward predictable patterns like Password1!. What matters is unpredictability measured in bits — length drawn from a large, random pool.

    Length beats symbols

    Adding one random character multiplies the search space far more than swapping a→@. A long passphrase usually beats a short “complex” password. Try the generator.

    Unique per site

    Even a strong password fails if it’s reused — one breach becomes many via credential stuffing. Generate a different password for every account and keep them in Apex.

    Password Strength Checker FAQ

    Common questions

    Is it safe to type my password into this checker?

    The check runs entirely in your browser using local JavaScript — your password is never transmitted, logged, or stored, and you can verify that in your browser’s Network tab. As a general security habit, though, you should avoid entering a password you actively use into any website. Test a freshly generated password, or change a character or two first.

    How is password strength measured?

    Strength is estimated from entropy: the number of bits of unpredictability, calculated as length × log2(character pool size), then reduced when common weaknesses are detected (dictionary words, repeats, keyboard sequences, trailing years). More bits means exponentially more guesses to brute-force.

    How many bits of entropy is strong?

    In 2026, ≥80 bits resists offline brute-force from a well-funded attacker, and ≥100 bits is comfortably future-proof. Below ~60 bits is weak for anything valuable. A 16-character random password drawn from all character classes reaches ~105 bits.

    Why does my long password still score low?

    Length helps only if the characters are unpredictable. “Password123!” is 12 characters but built from a dictionary word, a sequence, and a trailing symbol — all patterns attackers try first — so its real entropy is far lower than its length suggests.

    Does this checker tell me if my password was leaked?

    No. It evaluates strength offline and does not check breach databases (that would require a network request). To make any password unleakable in the first place, generate a unique random one per site and store it in a manager like Apex.

    Ready for the full vault?

    Stop reusing. Start sealing.

    Apex Password stores every credential end-to-end encrypted, on your device. The relay never sees plaintext.