Password generator
Create random passwords with selected character sets.
Longer passwords raise entropy faster than extra symbols.
Generated passwords
Strength checker
Paste or generate a password to estimate attack resistance.
Estimated crack time
Password strength report
Security checks
Recommendations
- At least 12 characters
- 16+ characters recommended
- Uses several character types
- No common words or passwords
- No obvious sequences
- No long repeated runs
What is this tool?
Password Generator & Checker creates strong random passwords in your browser and estimates how hard a password would be to crack. It reports entropy, score, character pool size and attack-time estimates without sending the password anywhere.
Passwords are generated and analyzed entirely in the browser. Nothing is uploaded, requested from an API or saved to local storage.
Features
- Generate multiple random passwords with uppercase, lowercase, numbers and symbols
- Use secure browser randomness with an option to exclude ambiguous characters
- Estimate entropy, score and crack time for online throttled, offline CPU and offline GPU attacks
- Flag short length, common words, sequences and repeated characters
- Copy individual passwords or download the generated list
How to use
-
Choose options
Set the password length, number of results and allowed character types.
-
Generate passwords
Click Generate to create local random passwords and review the first one immediately.
-
Check strength
Paste any password into the checker to see entropy, score, level and estimated crack time.
-
Copy or download
Copy a single password or download the generated list when you need several account credentials.
FAQ
Are passwords uploaded to a server?
No. Generation and checking run in the browser. The tool does not upload passwords or store them in local storage.
How is crack time estimated?
The estimate uses character-pool entropy and several attack speeds. Real attacks depend on hashing, leaks, rate limits and attacker hardware.
Does this check leaked password databases?
No. To stay fully local, it only checks common risky patterns, not online breach databases.
What length should I use?
Use at least 12 characters. For important accounts, 16 or more random characters is a stronger default.