Pasting your banking password into a random “strength checker” to see if it is safe is like shouting your PIN across a café to test the acoustics. Most checkers upload exactly what you type. This guide shows how to test password strength without sending it anywhere — local meters, zxcvbn logic, and reading the score like an attacker would.
Part of the password generator guide. Our password strength tester runs entirely in your tab — verify with DevTools Network panel showing zero requests. Theory in what makes passwords strong.
Local-first testing (the only safe kind)
A strength test is safe only if the secret never leaves your device. Before typing anything anywhere: open DevTools → Network, type a dummy, confirm no requests. Our tester passes — pure client-side scoring, offline-capable after load. Red flags elsewhere: no privacy statement, analytics calls on each keystroke, “save” or “check breach” buttons that POST plaintext (proper breach checks use k-anonymity prefixes, never full secrets). Rule: test patterns similar to your real passwords on third-party sites; test actual secrets only in verified-local tools. Better yet, generate fresh secrets in the generator and test those — nothing personal at stake.
How zxcvbn-style scoring actually works
Good meters (Dropbox's zxcvbn, open source since 2016) do not count character classes — they simulate attackers: dictionary matches (common passwords, names, words in 30+ languages), spatial patterns (qwerty, 12345), repeats (aaa), sequences (abcd), dates, and leet substitutions (a→@). Each match gets guess estimates; the weakest link scores. That is why “Tr0ub4dor&3” rates poorly despite ticking every complexity box, while a 5-word random passphrase rates highly. Score bands (0–4) map to crack resistance in orders of magnitude: 0–1 guessable within minutes, 2 resists casual online guessing, 3–4 effectively infeasible offline — illustrative, not year estimates.
| Score | Meaning | Action |
|---|---|---|
| 0–1 (weak) | Dictionary/pattern guessable | Regenerate immediately; never deploy |
| 2 (fair) | Resists casual guessing | OK for throwaway accounts only |
| 3 (strong) | Survives offline attacks practically | Minimum for email, bank, manager |
| 4 (excellent) | Brute-force infeasible | Ideal; still needs uniqueness + 2FA |
Reading your score like an attacker
- Score 3+ but reused? Still one breach away from everywhere — uniqueness outranks marginal score gains. Rotate the reused set first.
- Score 2 on a long password? It contains a guessable core (name, date, word). Keep the length, randomize the core — test again.
- Perfect 4 everywhere identical? Same failure. Generate unique 4s per site; the manager holds them all.
- After any breach notice: retest changed passwords, but prioritize the breach checklist order (breached + reused first) over perfecting scores.
Enterprise spot-checks (for teams without a security staff)
Small teams inherit the same threats with none of the tooling. Quarterly 30-minute ritual: export vault health reports (most managers flag reused/weak/exposed entries — clear to zero), verify every team member has MFA on email and cloud admin, rotate shared credentials after each departure within 24 hours, and test one restore (recovery codes actually work, backups actually open). Log results in one page: date, flags cleared, rotations done. Auditors and cyber-insurance questionnaires accept documented rituals over expensive platforms at small scale. The breach order scales to teams identically — contain shared accounts first, then individuals.
General information only, not security advice. Generate offline, store in a manager, enable MFA on email/bank. If you lose your master password it cannot be recovered by us.