Skip to content
UniKit

Password strength analyser

Estimate password entropy, detect weak patterns (digits only, keyboard runs, years, common words…) and project brute-force cracking time at several guess rates — all locally in your browser.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Show password

What this tool does

  • Check whether the password you actually use is strong enough: you immediately get its entropy, a strength rating and any weak patterns detected (digits only, keyboard runs, years, common words).
  • Investigate a "long but weak" password: a combination like String2024! has decent entropy yet is downgraded by pattern detection, which is exactly why appending a year is a bad idea.
  • Compare strategies: rewrite the same phrase as a passphrase or add one more character and watch how entropy and crack time move, so you can tell whether length or symbols help more.
  • Use it in training material: the three-attack-rate table (online API at 10⁶/s, single GPU slow hash at 10⁹/s, GPU cluster fast hash at 10¹²/s) is a concrete way to explain why slow hashing matters.

Example

Input

P@ssw0rd2024

Output

Length: 12
Charset size: 95
Entropy: 78.8 bits
Rating: fair
Weak patterns detected: contains a year
Estimated brute-force time: online API about 85673530 centuries / single GPU slow hash about 85674 centuries / GPU cluster fast hash about 86 centuries

The charset size of 95 is 26 uppercase + 26 lowercase + 10 digits + 33 ASCII symbols, and the entropy is 12 × log2(95) ≈ 78.84. That looks strong, but the "contains a year" pattern pulls the rating down to fair.

Frequently asked questions

Does high entropy mean the password is safe?

No. Entropy only reflects length × charset size, so a long string of repeated characters still scores high. That is why pattern detection runs alongside it: common passwords, common words, keyboard runs, sequential or repeated characters, years and dates all lower the rating. Read both results together.

How are common weak passwords detected?

About 108 common passwords are built in (password, 123456, qwerty, admin, iloveyou, woaini, 5201314 and similar, including pinyin and number puns). Matching one outright marks the password as very weak rather than simply dropping one level, because such entries are guaranteed to be in attack dictionaries.

What is the difference between the three crack times?

The same entropy is converted at three guess rates: an online rate-limited API at 10⁶/s, a single GPU on a slow hash at 10⁹/s and a GPU cluster on a fast hash at 10¹²/s. The spread is a factor of a million, which shows how a password can survive centuries under rate limiting and a slow hash yet fall in minutes on a fast-hash cluster.

Why does my 20-character password say "far beyond real time"?

Once entropy passes 1024 bits, the average guess count 2^(entropy-1) exceeds what a float can represent, so the tool reports infinity and shows "far beyond real time". That is expected behaviour, not a failed computation.

Can my password leak?

No. The analysis runs entirely in local JavaScript with no network requests and the password is never logged. Still, avoid typing real credentials on someone else's machine — the reveal toggle is only meant to help you spot a typo.

Keywords:密码强度password strengthentropy熵暴力破解brute force弱密码常见密码passphrase

Related tools