passcheck
Password strength checker — entropy, pattern detection and crack-time estimates, fully offline.
Check a password
Everything below runs in JavaScript on this page. Nothing is sent anywhere — same promise as the CLI.
The password field starts masked; toggle show to reveal it. Analysis never leaves this tab.
How the score works
- Start from
length × log2(pool)bits of brute-force entropy. - Subtract bits for every pattern an attacker tries first: common passwords, dictionary words, keyboard walks, sequences, repeats, years.
- Map the result:
<28very weak,<36weak,<60fair,<80strong, else very strong. - Crack time assumes an offline attack at 10¹⁰ guesses/second.
A passphrase is capped at ~12.9 bits per word (Diceware-sized list), because attackers guess words whole.
Patterns it looks for
- Whole-password hits on the built-in common list (
123456,qwerty, …) - Leetspeak un-mapping:
P@ssw0rd→password - Keyboard walks:
qwer,asdf,1qaz - Alphabet/digit sequences:
abcd,4321 - Repeats:
aaaaaaaa,ababab - Years and dates:
1998,03/04/2026
Port of src/passcheck/analyzer.py — same penalties, same thresholds.
02 Strength history (last 10 — scores only, never the passwords)
Each analysis appends a strength snapshot. The password itself is never stored — only score, entropy and length.
03 Crack time at multiple hash rates
Average time to exhaust half the keyspace (2ⁿ⁻¹ ÷ rate). Rates are realistic orders of magnitude for common scenarios.
bcrypt (cost 12) ≈ 10⁴ guesses/s per high-end GPU core cluster; online throttled ≈ 100/s against a login endpoint; GPU MD5 ≈ 10¹¹/s; offline fast hash ≈ 10¹⁰/s (matches the base estimate).
04 Batch mode
Paste one password per line — get a scored table. Useful for auditing an exported list (passwords stay in this tab).
05 Password generator
Cryptographically random via crypto.getRandomValues. Preview updates live with length and charset choices.
06 Entropy by character class
How many bits each class contributes if you add characters drawn uniformly from it. Combined pool entropy = length × log₂(sum of active class sizes).
07 zxcvbn-style feedback
Specific, actionable suggestions ranked by impact — what an attacker would exploit first, and how to close the gap.
CLI output (for comparison)
Run the real tool with passcheck — the numbers here should match its report for the same input.