Password Strength & Crack-Time Checker
Real entropy-based analysis of a password's actual strength and an estimated real-world crack time, computed locally · free, no signup
How Password Strength & Crack-Time Checker works, step by step

Type a password into the field (it's never sent anywhere).
Download itSee its real calculated entropy in bits.
Password Strength & Crack-Time Checker
This is a different tool from this site's Password Breach Checker (which checks a password against known leaked-password databases) and Password Generator (which creates new random passwords) — this one analyzes the actual strength of a password you're considering, computing its real character-set entropy in bits and then applying real, pattern-aware deductions for common weaknesses like dictionary words, keyboard patterns (qwerty, asdf), repeated characters and simple substitutions (like '@' for 'a') that a pure entropy formula alone would miss.
From the resulting effective entropy, it estimates a real, honestly-labeled crack time range under both a slow, rate-limited online guessing scenario and a fast offline brute-force scenario using current typical hardware guessing speeds — giving a concrete, real-world sense of 'how strong is strong enough', not just an abstract strength meter bar.
Key features
Real entropy calculation
Computes actual bits of entropy from the password's real character set and length, the mathematically correct base measure.
Pattern-aware deductions
Detects and penalizes dictionary words, keyboard-walk patterns, repeated characters and common substitutions a raw entropy number would miss.
Real crack-time estimate, two scenarios
Shows an estimated crack time under both online rate-limited and offline brute-force attack speeds.
Fully local, nothing transmitted
Unlike the breach checker (which safely queries a database), this tool never needs to send the password anywhere at all — pure local calculation.
How to use it
- Type a password into the field (it's never sent anywhere).
- See its real calculated entropy in bits.
- Review the pattern-based weaknesses detected, if any.
- See the estimated real-world crack time under both online and offline attack scenarios.
Worked example
Example
'Summer2024!' calculates a moderate raw entropy from its character set, but the pattern analysis detects a dictionary word ('Summer') plus a predictable year-and-symbol suffix, reducing its real effective strength significantly — estimated crack time might drop from a raw-entropy-implied 'centuries' down to a realistic 'under a day' once those common patterns are accounted for, versus a similar-length truly random string that keeps its full entropy.Who uses this tool
Anyone choosing a new account password
Get a real, pattern-aware strength read before committing to a password, not just a length check.
IT and security-conscious teams setting password policy guidance
Understand concretely how much common patterns weaken a password versus its raw length.
Anyone reusing or slightly modifying an old password
See how much a small variation (like adding a year) really helps or doesn't.
Tips for the best results
- Raw entropy alone overstates real-world strength if the password follows a common pattern — always check the pattern-based deductions, not just the bits-of-entropy number, for a realistic picture.
- Crack-time estimates are necessarily approximate and depend heavily on real attacker resources and whether rate-limiting is enforced — treat the numbers as a relative comparison between choices, not an exact guarantee.
- A long, truly random passphrase (several unrelated real words) often beats a shorter complex-looking password with obvious substitutions, because pattern-aware analysis catches predictable substitutions that pure length/complexity rules miss.
Common mistakes to avoid
- Judging password strength by length or character variety alone without accounting for real predictable patterns like dictionary words or keyboard walks.
- Reusing a 'strong-looking' password with a small tweak (like incrementing a number) across many accounts, which real attackers specifically anticipate and check for.
- Treating a good crack-time estimate as a permanent guarantee — re-check and update passwords periodically, and always pair a strong password with two-factor authentication where available.
Why use AZRS QuickFix?
It is 100% free, needs no signup and has no watermark or usage limits. The tool runs in your browser, so what you type stays on your device, and it works on phones, tablets and desktops. New tools are added every week — bookmark this page or browse the full QuickFix toolbox.
Frequently asked questions
Is my password ever sent anywhere to check this?
No — this is one of the few checks on the site that needs zero network transmission at all, since strength analysis and crack-time estimation are pure local calculations; nothing about your password ever leaves your browser.
How is this different from the Password Breach Checker?
The Breach Checker safely checks whether a password has appeared in known real data breaches (using a privacy-preserving method that never sends the full password). This tool instead analyzes the password's own inherent strength and estimates crack time — a genuinely different question that doesn't require checking against any external database at all.
How is 'crack time' actually estimated?
From the password's real effective entropy (raw character-set entropy minus real deductions for detected patterns), divided by a typical guesses-per-second rate for two real scenarios — a slow, rate-limited online login attempt, and a fast offline brute-force attempt — giving two different, honestly-labeled real-world estimates.
What patterns does it detect?
Common dictionary words, keyboard-adjacent sequences (like qwerty or asdf), simple character repetition, and common character substitutions (like '@' for 'a' or '0' for 'o'), all of which measurably reduce a password's real-world guessability below its raw entropy number.
Should I use this instead of the Password Generator?
They serve different steps — use the Password Generator to create a new strong random password, and this tool to evaluate the real strength of a password you already have in mind or are reusing.
Is my data stored?
No, nothing about the password you type is saved, logged or transmitted.