Password Strength Meter Widget

Add a password strength meter to your website. Visitors type a password and see an estimate of how guessable it is, what weakens it and rough time-to-guess bands, without the password ever leaving their browser.

Website & Security Tool Runs in your browser Free · no ads

Customize your widget

Theme
Auto follows the visitor's light/dark setting.
Style
Attribution on your page
Optional and entirely your choice. The exact line is shown in the code below; it links to the tool with rel="nofollow".
More options

Live preview

Exactly what your visitors will see

Embed code

<iframe src="https://a2z.tools/embed/w/password-strength-meter" title="Password Strength Meter by A2Z Tools" width="100%" height="720" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>

A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.

Works with

How it works

The widget computes two figures. The first is the textbook entropy of a randomly generated password: length times log2 of the character pool (lower case, upper case, digits and symbols). That is an upper bound, because people do not choose characters at random. The second is a guessing estimate that looks for the structure attackers exploit - a short built-in list of the most common passwords (also after undoing substitutions such as @ for a and 0 for o), repeated characters and chunks, sequences like abc or 9876, keyboard walks such as qwerty or asdf, and years and dates - and charges only a few bits for each pattern it finds. Words separated by spaces or hyphens are scored as a passphrase, as if each word came from a 7,776-word list. The lower figure is used, short passwords are capped at weak or fair, and time-to-guess is shown as broad bands for three attack speeds.

Method

  • Pool = 26 (a-z) + 26 (A-Z) + 10 (0-9) + 33 (symbols and space), + 100 for other characters
  • Random-equivalent entropy = length x log2(pool)
  • Guessing estimate = cheapest cover of the password by patterns (common password: log2(rank) + 1; sequence: log2(10 or 26) + 1 + log2(length); keyboard walk, repeat, year: a few bits; date: log2(365 x 200)) and plain characters (log2(pool) each)
  • Passphrase of n words = n x log2(7,776); estimate = the lowest of the figures
  • Levels: under 28 bits very weak, 28-35 weak, 36-59 fair, 60-79 strong, 80+ very strong; under 8 characters at most weak, under 12 at most fair
  • Time bands = 2^bits / 2 guesses at 10/s (online), 10,000/s (bcrypt-style) and 10^10/s (fast hash)

Worked examples

Substitutions do not help

Inputs: P@ssw0rd

Result: Very weak - about 2 bits by the guessing estimate, although its random-character bound is 52.6 bits

Undoing @ -> a and 0 -> o turns it into one of the most common passwords, so it costs only a few guesses.

A four-word passphrase

Inputs: correct horse battery staple

Result: Fair - 51.7 bits, scored as four words from a 7,776-word list

4 x log2(7,776) = 51.7 bits; a fifth random word would add another 12.9 bits.

Limitations

  • The built-in list of common passwords is deliberately short, so it cannot check against breach corpuses the way a server-side blocklist check under NIST SP 800-63B can.
  • Assumes the words of a passphrase were picked at random; a well-known phrase or song lyric is far weaker than the score suggests.
  • Time-to-guess bands assume fixed attack speeds; real speed depends on how each site stores passwords, which the widget cannot know.

Where publishers use it

  • Sign-up and account-security help pages that explain what makes a good password
  • IT and security awareness training for staff or students
  • Blog posts about password managers and passphrases
  • School computing lessons on entropy and brute-force attacks

Questions

Is the password sent anywhere?

No. The check runs entirely in the visitor's browser. The widget makes no network request with the password, does not save it and has no preset parameter for it, so it cannot appear in a URL or log.

Why does a password with symbols still score badly?

Because symbols do little when the structure is predictable. "P@ssw0rd" uses four character types but is one of the first things any attacker tries. Length and unpredictability matter far more.

How reliable are the crack-time bands?

They are rough. Real speed depends on how a site stores passwords, which the widget cannot know, and the pattern list is deliberately small. Treat the result as a guide, not a guarantee.

What makes a strong password?

Length first: a passphrase of several random words or a long password from a password manager, different for every site. Avoid names, dates, keyboard patterns and common words.

Sources

  1. NIST SP 800-63B Digital Identity Guidelines - Authentication and Authenticator Management - National Institute of Standards and Technology . Length over composition rules; compare new passwords against a blocklist of common and compromised ones
  2. EFF's new wordlists for random passphrases - Electronic Frontier Foundation, 2016 . 7,776-word list (6^5 dice rolls) behind the passphrase estimate

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools Password Strength Meter
https://a2z.tools/password-entropy-calculator
  • Browser Info

    Website & Security Tool

    Shows the visitor's browser, OS, screen, language, time zone and other settings - read locally.

  • My IP Address

    Website & Security Tool

    Shows the visitor's public IPv4 or IPv6 address as A2Z sees it, with a copy button.

  • SSL Certificate Badge

    Website & Security SVG badge

    A live badge showing that your SSL certificate is valid, trusted and how many days it has left.

  • SSL Expiry Badge

    Website & Security SVG badge

    A badge counting down the days until your SSL certificate expires.

  • HTTPS Badge

    Website & Security SVG badge

    Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.

  • HSTS Badge

    Website & Security SVG badge

    Shows whether your site sends HTTP Strict Transport Security, with max-age and preload.

Preview