Everyday calculator
Password Strength Checker, Crack Time & Security Score
Check your password strength and see estimated crack time, character analysis, and specific suggestions to make it stronger. 100% local, never sent to any server.
How CalcMesh evaluates password strength
We estimate strength from length and character variety, the factors that drive entropy. According to the National Institute of Standards and Technology guideline SP 800-63B, length matters more than forced complexity, and long passphrases are encouraged.
All evaluation runs entirely in your browser, your password is never sent to a server, and the entropy model we use is described in our methodology.
Password Security Guide
Password Best Practices
- Length over complexity: A 16-character password with only lowercase letters has more entropy than a random 8-character password with all character types.
- Unique per site: Never reuse passwords. If one account is breached, all accounts with the same password are compromised.
- Avoid personal info: Names, birthdays, pet names, and addresses are among the first things attackers try.
- No common patterns: Avoid "Password1!", "qwerty", "abc123", and keyboard patterns like "zxcvbn".
The Passphrase Approach
Instead of a complex password like "J#7kQ!9m", consider a passphrase of 4-6 random words:
- "maple-candle-orbit-frozen" (easy to remember, very strong)
- "correct horse battery staple" (the classic XKCD example)
Random word passphrases are both stronger and easier to remember than short complex passwords. The key is using truly random words, not song lyrics or famous quotes.
Password Managers
A password manager is the best way to maintain unique, strong passwords for every account. Recommended options:
- 1Password: User-friendly, family sharing, travel mode
- Bitwarden: Open source, free tier available
- KeePassXC: Fully offline, open source
Enable Two-Factor Authentication
Even a strong password can be stolen in a data breach. Two-factor authentication (2FA) adds a second layer of security. Prefer authenticator apps (like Authy or Google Authenticator) over SMS codes, as SMS can be intercepted via SIM swapping.
Note: This tool provides a rough estimate of password strength. Real-world attack resistance depends on the hashing algorithm used by the service and the attacker's resources.
Worked example, entropy of two candidates
Browser-local estimate only (NIST SP 800-63B favors length; this checker scores charset × length):
Tr0ub4dor&3style short complex: ~11 chars, mixed class → often lands Fair / ~40-50 bits here; dictionaries still crack variants fast.maple-candle-orbit-frozen(4 random words + hyphens): 25 chars, mostly lowercase → typically Strong / 60+ bits under the same charset model because length dominates.- Adding a digit + symbol to the passphrase usually moves the meter one band without needing punctuation soup.
- Reuse of either string across sites is scored the same locally - the meter cannot see breaches; uniqueness is outside the formula.
After you check a string
What to do with the score
- Prefer length (passphrase) over forced symbol soup when the meter and NIST guidance agree.
- A green local score does not mean the site hashes well - still use a manager + unique password per account.
- Turn on app-based 2FA; SMS 2FA is weaker against SIM swap than TOTP.
- Never paste real production passwords into any third-party page; this tool stays in-browser on purpose.
Methodology & Assumptions
This calendar tool counts civil days and applies stated unit rates to the dates and distances you enter. Time-zone edges follow the browser zone database for your inputs.
How this calendar node runs
Date and rate tools count civil days and apply stated unit rates. Zone edges follow the browser zone database. Published domain formulas
govern the identities; when an agency updates rates or thresholds we refresh defaults
and the page lastmod.
| Input | Default | Source / authority |
|---|---|---|
| All inputs | Domain-typical defaults | Editorial methodology, CalcMesh 2026 |