Breach exposure
Password checker
Two checks in one: a local strength analysis (entropy, common patterns, realistic crack time), and a lookup against known breach-password lists using k-anonymity. Your full password is never transmitted, only a five-character hash fragment leaves the browser.
Password strength is not a feeling and it is not a count of symbol types. It is a mathematical estimate of how many guesses an adversary must try before your secret appears, compared to how many guesses they can afford to try per second on hardware that keeps getting cheaper. The two strongest predictors are length and unpredictability, not the number of character classes the creation form demanded.
This page gives you both halves: an instant local estimate of entropy, pattern risk and realistic crack time, and an optional leak lookup against billions of known compromised passwords carried out so that your full password never leaves the browser.
What the instant strength estimate tells you
The strength panel runs entirely in your tab. It measures raw entropy, flags common structures like dictionary words, keyboard walks, repeated runs and simple substitutions that cracking dictionaries encode explicitly, and translates that into crack-time bands for offline and online attacker models. A four-word random passphrase regularly outranks an eight-character symbol soup precisely because each additional random word multiplies the search space by thousands while remaining typable.
That estimate is conservative by design: attackers do not try every combination naively, they prioritize human-chosen patterns. So a short complex string that matches a common template is correctly called weak even though its character set looks varied.
- Length dominates: each additional random character or word multiplies possibilities exponentially.
- Repetition and pattern collapse the space: 'aaaa', '1234', 'qwerty' and leetspeak swaps are pre-computed.
- Uniqueness matters more than brilliance: a strong password reused across accounts is strong everywhere until one leak makes it weak everywhere.
How the leak check uses k-anonymity
The leak database holds SHA-1 hashes of hundreds of millions of compromised passwords. Rather than sending your password, the page hashes it locally, transmits only the first five hex characters of that hash, and receives back all hash suffixes that share that prefix. Your browser completes the comparison locally and reports whether an exact match exists and how many times that password has been seen.
Only a small fragment leaves the device, and that fragment is shared with thousands of other users, making reversal infeasible. The approach, popularized by Have I Been Pwned's range API, means even a network observer cannot learn the candidate you tested beyond the coarse prefix.
Reading a result honestly
Strength and exposure are separate axes. A string can be structurally strong and still be compromised because someone else chose the same string and then leaked it, 'correct-horse-battery-staple' as a quoted example paradoxically became weak once it was printed in an article. Conversely, a structurally weak string that is not in the current corpus is still weak because the first offline brute force will find it.
If the leak check says your password has been seen, rotate it everywhere you used it, starting with email and banking. If it says it has not been seen, judge it by the strength estimate: length and randomness still decide whether it would survive the next database dump.
A practical migration path
No one should memorize 150 unique high-entropy secrets. Choose one strong master passphrase you can type reliably, provision a reputable password manager with it, and let the generator create per-site secrets you never need to recall. Replace reused or leaked passwords over two weeks rather than in a marathon, but start with the three that gate recovery: your primary email, your password manager, and your cloud backup.
Store printed recovery codes for those three offline. A vault that cannot be recovered after a lost device helps no one.
Test the passwords you actually rely on today, not toy examples, and treat any leak hit as same-day work. Adopting a manager this week does more for long-term exposure than any clever composition trick.
How it works
Type or paste the password. Strength analysis happens instantly on your device.
Press "Check leaks" to query the leak database using only a hash prefix.
The browser compares results locally and tells you whether this exact password has appeared in breaches.
Questions about this tool
Can you see the password I type?
No. The page hashes it with SHA-1 in your browser and sends only the first five characters of that hash to the leak database. The server replies with a list of possible matches; your browser does the comparison.
What actually makes a password strong?
Length first, randomness second. A four-word random passphrase outperforms most eight-character symbol soups. And never reuse one password across sites, reuse is how single breaches turn into account takeovers.
It says "seen 300 times", what now?
It means this exact password is in public leak compilations. Attackers feed those lists into automated login attempts, so change it everywhere you use it, starting with email and banking.