Password Entropy Meter
This runs entirely in your browser. Nothing is sent anywhere.
What is Password Entropy?
Password entropy is a measure of how unpredictable a password is. It is measured in "bits". The higher the entropy, the harder it is for an attacker to guess or crack your password using brute-force methods.
How many bits do you need?
- < 28 bits: Very Weak. Can be cracked instantly.
- 28 - 35 bits: Weak. Vulnerable to simple attacks.
- 36 - 59 bits: Reasonable. Good for low-risk accounts.
- 60 - 127 bits: Strong. Recommended for most online services.
- 128+ bits: Very Strong. Necessary for encryption keys and high-security access.
Character Pool
- Lowercase Letters 26 chars
- Uppercase Letters 26 chars
- Numbers 10 chars
- Shift + [0-9] Symbols 10 chars
- Other Symbols 23 chars
- Total 0 chars
Result
Start typing to see the entropy score
~0 Bits
Understand Password Entropy and Real‑World Strength
Entropy estimates how hard a password is to guess by measuring the size of the character pool and the length of the secret. While not a guarantee, it’s a practical proxy for resisting brute‑force attempts.
What Drives Entropy
- Length: Each extra character multiplies the search space.
- Diversity: Mixing letters, numbers, and symbols increases the pool.
- Predictability: Common patterns reduce effective entropy.
Recommendations
- Prefer long passphrases or 16+ character passwords when allowed.
- Avoid predictable substitutions (P@ssw0rd!), which tools already account for.
- Use MFA and a password manager instead of memorizing many secrets.