See what an attacker sees.
Type any password. The lab runs the same kinds of checks a cracking tool would try first, then explains the result in plain words.
A password strength checker is only useful if it thinks like the software attackers actually use. This one does not just count character types: it checks the password against the 1,500 most common leaked passwords, undoes the usual letter-for-symbol swaps, and looks for seasons-plus-years, keyboard walks, repeats and the capital-word-digits template. The result is an estimate of how many guesses the password would really survive, and how long that would take.
Type a password you actually use if you like: the page makes no network requests while you type and nothing is stored. Or start with one of the examples.
Runs entirely in your browser. Nothing you type is sent, logged, or saved, and the page makes no network requests when you type.
Waiting for a password
The verdict, the reasons, and a rough time-to-crack will appear here as you type.
The time-to-crack figures are estimates. "Offline" assumes an attacker has stolen a database of poorly protected password hashes and is guessing on their own hardware. "Online" assumes they are guessing against a live login that slows them down. Either way: a password manager that generates long random passwords, plus two-factor sign-in, removes most of the risk.
Attackers do not guess passwords by hand. They run software that tries leaked lists, dictionary words, seasons-plus-years and keyboard walks, millions of times a second, and then applies "rules" like capitalising the first letter or swapping o for 0. The lab mirrors those rules so you can see which of your habits are already in the attacker's playbook.
The effective-bits figure is a rough measure of how many guesses the password would survive after those patterns are accounted for. Raw "character variety" scores overstate strength; this one tries not to.