Passphrase Strength Meter

Type a passphrase and watch it get taken apart the way a cracking tool would take it apart: words, dates, runs and repeats get named, and what is left over is the only part anyone has to actually guess.

Your passphrase

Everything happens in this tab. Nothing is stored, nothing is remembered, and this page makes no network requests of any kind — you can watch the network panel while you type.

Try one

How hard is it to guess?

estimate, not a promise
0 bits of
guesswork
EMPTY

Every extra bit doubles the work. 30 bits is a coffee break, 45 is an afternoon, 60 is a real wall, and past 75 nobody is getting in by guessing — they will phone you and ask instead.

Time to guess it, on average

What a cracker sees

cheapest split found, left to right

What to do about it

How this number is worked out

The meter tries every way of chopping your passphrase into known patterns — a word list of about 450 entries baked into this page, dates and years, counting runs like 4567 or wxyz, repeats like lolololol, and keyboard walks like asdfg — and then picks the split that would cost an attacker the least. Anything the meter can't name is priced as raw brute force over the characters you actually used.

Substitutions are priced honestly: @ for a and 0 for o are tried by every real tool, so they buy a bit or two, not a category. Splitting a passphrase into several parts does cost the attacker something (they have to guess the shape too), so the meter adds a penalty for each extra piece. And if the text is stitched together with function words — the, is, my, for — it is treated as running English and capped at about 1.2 bits per character, because a sentence you composed is far weaker than the same letters drawn at random. Four unrelated words are not a sentence and keep their full price.

Bits is just the base-2 logarithm of that guess count. Each extra bit doubles the work. Times assume the attacker gets the answer halfway through, on average.

Where it lies to you: the word list here is tiny — real attack dictionaries carry hundreds of millions of leaked passwords, names and phrases. If your passphrase leans on a word this page has never heard of, the meter will price it as random and flatter you. Treat the number as a ceiling, never a floor.