How this estimates strength
A meter that counts character classes measures the wrong thing. It asks whether you
used an uppercase letter, a digit and a symbol, and P@ssw0rd! says yes to
all three. But nobody samples the space of all nine-character strings. They run a list,
and password is near the top of it.
This tool estimates guesses: how many attempts a well-equipped attacker needs before yours comes up. It breaks what you typed into the cheapest set of patterns that covers the whole string, prices each pattern, and multiplies.
What it looks for
- Common passwords — a ranked list of the most-reused ones. Position in the list is the guess count: a top-ten password costs ten guesses.
- Words and names — English words, first names and surnames, forwards and backwards.
- l33t substitutions —
@fora,0foro,3fore. Cracking tools apply these automatically: a small multiplier, not a new password. - Keyboard walks —
qwerty,asdfgh,1qaz2wsx. Priced by length and by how often the path turns. - Dates and years — a four-digit year is worth about as much as a two-digit number, because almost nobody picks 1673.
- Sequences and repeats —
abcdef,123456,aaaaaaaa. - Anything left over is priced as brute force over the classes you used.
The parts are then combined with a penalty per extra pattern, because searching combinations of patterns is more work than running one list.
Why the attack model is a control you can switch
Guesses become a time only once you say how fast the attacker can guess, and that spans about fourteen orders of magnitude. A password that holds off a throttled login form for a century falls in minutes to a GPU rig working on a stolen hash. Switch the control and watch the verdict move; the password did not change.
You do not get to pick which model applies to you. The service you gave the password to picked it when they chose how to store it, and you find out which after the breach. Hence the worst case by default, and hence a breach check being the other half of this question.
Nothing you type leaves this page
No form element, no submit button, and no request anywhere in this page carrying what you type. The password sits in a text field until you close the tab. Our analytics records that the tool was used and one of three words — weak, fair or strong — never a length, a character count or a hash.
Where this estimate is optimistic
Our lists hold a few thousand entries. A real rig loads hundreds of millions, plus every password from every public breach, plus rules that mutate each one a hundred ways. So when the tool says a password is on its list, believe it. When it says unknown, that means unknown to us — a ceiling, not a floor.
Read next: Why password strength meters lie · Passkeys vs passwords vs 2FA