Type a password (or a length) and pick the character pool. This tool computes Shannon entropy in bits and estimates offline crack time — entirely in your browser, nothing is sent anywhere.
Default 1e11 ≈ a single high-end GPU rig against fast unsalted hashes (e.g. NTLM/MD5). Slow salted hashes (bcrypt) are far lower.
Password entropy measures how unpredictable a secret is, expressed in bits. Assuming each character is drawn uniformly and independently from a pool of R possible symbols, a password of length L has RL equally likely values. The information content — the entropy — is the base-2 logarithm of that count:
This tool detects which character classes you actually used and sums their sizes to get R: 26 lowercase, 26 uppercase, 10 digits, and 33 printable ASCII symbols — a maximum pool of 95. So an 8-character password using lowercase + digits draws from R = 36, giving H = 8 × log₂(36) ≈ 41.4 bits. Each extra character adds a fixed log₂(R) bits, which is why length dominates strength far more than swapping in a single symbol.
To turn bits into time, the calculator computes the keyspace 2H and assumes an attacker must search, on average, half of it before a hit. Dividing by your guess rate yields the expected offline cracking time:
One important honesty note for bug-bounty and pentest work: this is the theoretical maximum entropy for a random string of that composition. Real human passwords — dictionary words, dates, l33t substitutions, keyboard walks — are not uniformly random, so their effective entropy is much lower than the formula suggests. Tools like zxcvbn model those patterns; this calculator gives the upper bound. Use it to compare composition policies and to sanity-check why an 18-character random passphrase beats a clever 8-character one every time.