Nouplo

Password strength checker

How long it would actually hold up.

Output
Paste or type above to see the result here.

Your files stay on your device

This tool runs entirely in your browser. What you paste is processed on your device and is never sent to a server, so it is safe to use with tokens, keys and unpublished text.

How it works

  1. Type or paste the password. It is masked in the output.
  2. Read the strength in bits — how many guesses an attacker faces.
  3. Read the warnings underneath. They are the part that matters.
  4. Several at once is fine, one per line.

Frequently asked questions

Is it safe to type a real password here?
It is checked in your browser and never transmitted, so it is safer than any page that sends one to a server. Even so: if you are unsure about a site, do not paste a real password into it. Type something with the same shape instead.
Why is my long password rated badly?
Length only helps when the password is not guessable another way. “Password123!” is twelve characters and is one of the first few thousand things any cracker tries; “qwertyuiop” is ten and is a row of the keyboard. The warnings say which pattern was spotted.
How accurate is the estimate?
It is a rough model and the page would rather say so. It counts the alphabet and the length, then takes off what the obvious patterns give away. A real estimate needs a dictionary of hundreds of millions of leaked passwords, which is a download rather than a page. Treat the number as a floor.
What actually makes a good password?
Length, and not being reused. Four or five random words beat a short string of symbols, and a different one everywhere beats a strong one used twice. A password manager makes both of those easy; our generator makes one if you need it now.
Is anything sent to a server?
No. It runs in your browser, so what you paste stays on your computer.

Related tools