Password Entropy Calculator
Measure the mathematical strength of your passwords using bit entropy to determine how resistant they are to brute-force attacks.
Runs in your browser Your input never leaves your device.
About this tool
Type a password to estimate its entropy, a rough measure of how many guesses a brute-force attack would need. The tool checks which character types you used, adding to a pool size: 26 for lowercase, 26 for uppercase, 10 for digits and 33 for any other symbol. Entropy is length x log2(pool). The strength label uses an effective entropy that subtracts for repeated characters, sequential runs and common passwords, so the label can be lower than the raw figure (both are shown). Labels are Very weak below 28 bits, Weak from 28, Reasonable from 36, Strong from 60 and Excellent from 128. The password is processed locally and not sent anywhere. This is a rough estimate: the raw figure assumes random characters, and the penalties only cover simple patterns and a short list of common passwords.
How to use it
- Type or paste a password to test.
- Read the length, character pool, entropy and strength label.
- Add length or mix character types to raise the score.
Example
The naive figure is 65.7 bits, but the password is very common, so it is rated Very weak.
Password1!
Length: 10 Character pool: 95 Entropy (random-character estimate): 65.7 bits Effective entropy (after pattern penalties): 20.0 bits Strength: Very weak Warning: this is, or is built on, a very common password; attackers try these first
Common problems
- A well-known password still looks strong in the raw entropy
- The raw entropy figure ignores dictionaries; the Strength label applies penalties for common passwords, repeats and runs, but only for a short built-in list. Never use common words, even with substitutions.
- A long passphrase scores lower than expected
- Only character types are counted, so four random lowercase words still use a pool of 26. Length matters most, so add more words.
- Should I test my real password?
- The text stays in your browser, but it is safer to test a similar one than your actual password.