Everyday calculator
Password Strength Checker, Crack Time & Security Score
Check your password strength and see estimated crack time, character analysis, and specific suggestions to make it stronger. 100% local, never sent to any server.
How CalcMesh evaluates password strength
We estimate strength from length and character variety, the factors that drive entropy. According to the National Institute of Standards and Technology guideline SP 800-63B, length matters more than forced complexity, and long passphrases are encouraged.
All evaluation runs entirely in your browser, your password is never sent to a server, and the entropy model we use is described in our methodology.
Password Security Guide
Password Best Practices
- Length over complexity: A 16-character password with only lowercase letters has more entropy than a random 8-character password with all character types.
- Unique per site: Never reuse passwords. If one account is breached, all accounts with the same password are compromised.
- Avoid personal info: Names, birthdays, pet names, and addresses are among the first things attackers try.
- No common patterns: Avoid "Password1!", "qwerty", "abc123", and keyboard patterns like "zxcvbn".
The Passphrase Approach
Instead of a complex password like "J#7kQ!9m", consider a passphrase of 4-6 random words:
- "maple-candle-orbit-frozen" (easy to remember, very strong)
- "correct horse battery staple" (the classic XKCD example)
Random word passphrases are both stronger and easier to remember than short complex passwords. The key is using truly random words, not song lyrics or famous quotes.
Password Managers
A password manager is the best way to maintain unique, strong passwords for every account. Recommended options:
- 1Password: User-friendly, family sharing, travel mode
- Bitwarden: Open source, free tier available
- KeePassXC: Fully offline, open source
Enable Two-Factor Authentication
Even a strong password can be stolen in a data breach. Two-factor authentication (2FA) adds a second layer of security. Prefer authenticator apps (like Authy or Google Authenticator) over SMS codes, as SMS can be intercepted via SIM swapping.
Note: This tool provides a rough estimate of password strength. Real-world attack resistance depends on the hashing algorithm used by the service and the attacker's resources.
Methodology & Assumptions
This calculator implements standard formulas drawn from primary-source authorities. Values are point-in-time estimates; consult a licensed professional for high-stakes decisions. See the per-input definitions and source citations below.
How this works
Computations are deterministic and run client-side, no inputs leave your
browser. Formulas are derived from
standard published formulas for the calculator's domain (mortgage,
taxes, energy, conversions, etc.). When the underlying agency publishes
updated rates or thresholds we refresh defaults and update the page's
lastmod timestamp.
| Input | Default | Source / authority |
|---|---|---|
| All inputs | Domain-typical defaults | Editorial methodology, CalcMesh 2026 |