← All projects
Security & networking · Python
P

passcheck

Password strength checker — entropy, pattern detection and crack-time estimates, fully offline.

Check a password

Everything below runs in JavaScript on this page. Nothing is sent anywhere — same promise as the CLI.

The password field starts masked; toggle show to reveal it. Analysis never leaves this tab.

very weak
0.0 bits
Score
0 / 4
Length
0
Pool size
0
Offline crack time
instantly

How the score works

  1. Start from length × log2(pool) bits of brute-force entropy.
  2. Subtract bits for every pattern an attacker tries first: common passwords, dictionary words, keyboard walks, sequences, repeats, years.
  3. Map the result: <28 very weak, <36 weak, <60 fair, <80 strong, else very strong.
  4. Crack time assumes an offline attack at 10¹⁰ guesses/second.

A passphrase is capped at ~12.9 bits per word (Diceware-sized list), because attackers guess words whole.

Patterns it looks for

  • Whole-password hits on the built-in common list (123456, qwerty, …)
  • Leetspeak un-mapping: P@ssw0rd → password
  • Keyboard walks: qwer, asdf, 1qaz
  • Alphabet/digit sequences: abcd, 4321
  • Repeats: aaaaaaaa, ababab
  • Years and dates: 1998, 03/04/2026

Port of src/passcheck/analyzer.py — same penalties, same thresholds.

02 Strength history (last 10 — scores only, never the passwords)

Each analysis appends a strength snapshot. The password itself is never stored — only score, entropy and length.

No checks yet — analyze a password above.

03 Crack time at multiple hash rates

Average time to exhaust half the keyspace (2ⁿ⁻¹ ÷ rate). Rates are realistic orders of magnitude for common scenarios.

ScenarioHash rateTime to crack

bcrypt (cost 12) ≈ 10⁴ guesses/s per high-end GPU core cluster; online throttled ≈ 100/s against a login endpoint; GPU MD5 ≈ 10¹¹/s; offline fast hash ≈ 10¹⁰/s (matches the base estimate).

04 Batch mode

Paste one password per line — get a scored table. Useful for auditing an exported list (passwords stay in this tab).

05 Password generator

Cryptographically random via crypto.getRandomValues. Preview updates live with length and charset choices.

—

06 Entropy by character class

How many bits each class contributes if you add characters drawn uniformly from it. Combined pool entropy = length × log₂(sum of active class sizes).

Check a password to see the breakdown.

07 zxcvbn-style feedback

Specific, actionable suggestions ranked by impact — what an attacker would exploit first, and how to close the gap.

CLI output (for comparison)

Run the real tool with passcheck — the numbers here should match its report for the same input.

$ passcheck
31 tests · Python 3.10+ · no dependencies · Built by Umer Hashmi