Theoretical entropy
The calculation uses length and character sets. It is transparent, but it can overestimate passwords with known words or patterns.
Estimate theoretical entropy, detect predictable patterns and compare attack times without sending your password outside the browser.
Local assessment
Interface limit: 256 Unicode code points. Do not use this tool as an account verifier in real high-risk situations.
Leaked hash with common hardware.
Leaked fast hash: 1000000000 intentos/s
Theoretical entropy = length × log2(character-set size). The practical assessment can lower the rating when it detects words, sequences, repetitions, dates or obvious substitutions.
0 × log2(0) = 0 bits
Entropy helps estimate combinations, but actual guessing difficulty depends on patterns and context.
The calculation uses length and character sets. It is transparent, but it can overestimate passwords with known words or patterns.
The tool penalizes common passwords, sequences, dates, repetitions and obvious substitutions such as replacing letters with numbers.
A rate-limited service does not behave like a leaked hash tested offline with specialized hardware.
No. The calculation runs in the browser, and the tool does not store, send or add the password to the URL.
They are a way to estimate the size of the search space. More bits generally mean more possible combinations, although they do not guarantee real security.
Because it may include common words, sequences, dates or repetitions that an attacker would try before a fully random search.
Yes, if it is unique and does not use a popular phrase. Length adds a great deal and is often easier to remember than obvious substitutions.
No. Risk also depends on breaches, phishing, malware, password reuse, MFA and service policies.
An online attack usually has attempt limits. An offline attack occurs when a hash has leaked and can be tested many times per second.
Yes. A manager helps create long, unique passwords, while MFA or passkeys reduce risk if a password is leaked.