Pemeriksa Kekuatan Sandi - Uji Bebas Keamanan Sandi Anda

Security Tool

PasswordStrength Checker

Test how strong your password is โ€” get entropy score, crack time estimate, breach check, and specific improvement tips. Nothing is stored or sent to any server.

100% CLIENT-SIDE BREACH DATABASE CHECK ENTROPY ANALYSIS
Enter Password to Test
๐Ÿ”’ YOUR PASSWORD NEVER LEAVES YOUR BROWSER โ€” NOT SENT TO ANY SERVER
๐Ÿ”
Type a password above to see the analysis
Store Your Strong Passwords with NordPass โ€” Free โ†’
Frequently Asked Questions
Is my password sent to your server?+
No. Everything in this tool runs entirely in your browser using JavaScript. Your password is never transmitted to blockaway.in or any third party. The breach check uses a k-anonymity technique โ€” only the first 5 characters of a SHA-1 hash are sent to the Have I Been Pwned API, making it impossible to reconstruct your actual password from the request.
How is entropy calculated?+
Entropy is calculated as: log2(charset_size) ร— password_length, where charset_size is the number of distinct character types in the password (lowercase a-z = 26, uppercase A-Z = 26, digits 0-9 = 10, symbols = 32). Higher entropy means exponentially more possible passwords, making brute-force attacks harder. Each additional bit of entropy doubles the search space.
What makes a password truly strong?+
Length matters more than complexity. A 20-character password using only lowercase letters has more entropy than a 10-character password using every character type. The combination of length (16+ characters), mixed character types, no dictionary words, and no personal information creates the strongest passwords. A passphrase โ€” four random words joined together โ€” is often both strong and memorable.
What does the breach check actually do?+
The breach check queries the Have I Been Pwned database โ€” a collection of over 10 billion compromised passwords from data breaches worldwide. It uses k-anonymity: your browser computes a SHA-1 hash of your password, sends only the first 5 characters to the API, and the API returns all hashes starting with those 5 characters. Your browser then checks locally whether your full hash appears in the results. Your actual password never leaves your device.
My password is strong but still appeared in breaches โ€” why?+
A breach result means your exact password was found in a leaked database โ€” not that someone cracked it. This happens when a service you used was hacked and stored your password in plaintext or with weak encryption. Even a strong, unique password can appear in breach databases if the site that stored it had poor security. If your password appears in breaches, change it immediately on all services where you use it.
IndonesiaidIndonesiaIndonesia