Password Strength Meter Widget
Add a password strength meter to your website. Visitors type a password and see an estimate of how guessable it is, what weakens it and rough time-to-guess bands, without the password ever leaving their browser.
Live preview
Exactly what your visitors will seeUnder the widget on your page: Powered by A2Z Tools
Embed code
<iframe src="https://a2z.tools/embed/w/password-strength-meter" title="Password Strength Meter by A2Z Tools" width="100%" height="720" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>
A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.
<div data-a2z-widget="password-strength-meter" data-height="720"></div> <script async src="https://a2z.tools/embed.js"></script>
Adds a small script (what it does) that sizes the widget to fit its content, loads it lazily and keeps it isolated from your page's CSS.
Works with
How it works
The widget computes two figures. The first is the textbook entropy of a randomly generated password: length times log2 of the character pool (lower case, upper case, digits and symbols). That is an upper bound, because people do not choose characters at random. The second is a guessing estimate that looks for the structure attackers exploit - a short built-in list of the most common passwords (also after undoing substitutions such as @ for a and 0 for o), repeated characters and chunks, sequences like abc or 9876, keyboard walks such as qwerty or asdf, and years and dates - and charges only a few bits for each pattern it finds. Words separated by spaces or hyphens are scored as a passphrase, as if each word came from a 7,776-word list. The lower figure is used, short passwords are capped at weak or fair, and time-to-guess is shown as broad bands for three attack speeds.
Method
- Pool = 26 (a-z) + 26 (A-Z) + 10 (0-9) + 33 (symbols and space), + 100 for other characters
- Random-equivalent entropy = length x log2(pool)
- Guessing estimate = cheapest cover of the password by patterns (common password: log2(rank) + 1; sequence: log2(10 or 26) + 1 + log2(length); keyboard walk, repeat, year: a few bits; date: log2(365 x 200)) and plain characters (log2(pool) each)
- Passphrase of n words = n x log2(7,776); estimate = the lowest of the figures
- Levels: under 28 bits very weak, 28-35 weak, 36-59 fair, 60-79 strong, 80+ very strong; under 8 characters at most weak, under 12 at most fair
- Time bands = 2^bits / 2 guesses at 10/s (online), 10,000/s (bcrypt-style) and 10^10/s (fast hash)
Worked examples
Substitutions do not help
Inputs: P@ssw0rd
Result: Very weak - about 2 bits by the guessing estimate, although its random-character bound is 52.6 bits
Undoing @ -> a and 0 -> o turns it into one of the most common passwords, so it costs only a few guesses.
A four-word passphrase
Inputs: correct horse battery staple
Result: Fair - 51.7 bits, scored as four words from a 7,776-word list
4 x log2(7,776) = 51.7 bits; a fifth random word would add another 12.9 bits.
Limitations
- The built-in list of common passwords is deliberately short, so it cannot check against breach corpuses the way a server-side blocklist check under NIST SP 800-63B can.
- Assumes the words of a passphrase were picked at random; a well-known phrase or song lyric is far weaker than the score suggests.
- Time-to-guess bands assume fixed attack speeds; real speed depends on how each site stores passwords, which the widget cannot know.
Where publishers use it
- Sign-up and account-security help pages that explain what makes a good password
- IT and security awareness training for staff or students
- Blog posts about password managers and passphrases
- School computing lessons on entropy and brute-force attacks
Questions
Is the password sent anywhere?
No. The check runs entirely in the visitor's browser. The widget makes no network request with the password, does not save it and has no preset parameter for it, so it cannot appear in a URL or log.
Why does a password with symbols still score badly?
Because symbols do little when the structure is predictable. "P@ssw0rd" uses four character types but is one of the first things any attacker tries. Length and unpredictability matter far more.
How reliable are the crack-time bands?
They are rough. Real speed depends on how a site stores passwords, which the widget cannot know, and the pattern list is deliberately small. Treat the result as a guide, not a guarantee.
What makes a strong password?
Length first: a passphrase of several random words or a long password from a password manager, different for every site. Avoid names, dates, keyboard patterns and common words.
Sources
- NIST SP 800-63B Digital Identity Guidelines - Authentication and Authenticator Management - National Institute of Standards and Technology . Length over composition rules; compare new passwords against a blocklist of common and compromised ones
- EFF's new wordlists for random passphrases - Electronic Frontier Foundation, 2016 . 7,776-word list (6^5 dice rolls) behind the passphrase estimate
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools Password Strength Meter https://a2z.tools/password-entropy-calculator
<a href="https://a2z.tools/password-entropy-calculator">A2Z Tools Password Strength Meter</a>
[A2Z Tools Password Strength Meter](https://a2z.tools/password-entropy-calculator)
Password Strength Meter by A2Z Tools - https://a2z.tools/password-entropy-calculator
Related widgets
-
Shows the visitor's browser, OS, screen, language, time zone and other settings - read locally.
-
Shows the visitor's public IPv4 or IPv6 address as A2Z sees it, with a copy button.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.
-
Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.