Review fictional password patterns locally. Calculate conditional random-model entropy and hypothetical guess time with declared pool size and guess rate.
Use a fictional example to explore password length and predictable patterns. The checker reports a few common patterns without sending the input to a breach service. A typed string alone cannot reveal how randomly it was generated, so entropy and guessing time are withheld by default.
How to use
Enter a test password or choose Sample. The field is hidden by default; Show test password reveals it locally. Select Compare / Check. The sample Password123! is intentionally predictable. Clear removes the input and report. The report does not repeat the password and there is no password-file download.

How the comparison works
Pattern review flags fewer than 15 Unicode code points, a small list of common password roots and simple substitutions, repeated characters or blocks, selected keyboard/alphabet/digit sequences, and year-like numbers. No listed pattern detected is not a security guarantee. This small heuristic list is not a full dictionary or breach corpus.
Details
For a conditional calculation, enable the random-generation declaration. Enter the actual pool size used by the generator and a hypothetical guesses-per-second rate. For length L and pool size R, entropy is L × log2(R) bits only under independent uniform selection. Approximate average exhaustive search time is 2^(bits−1) ÷ guesses-per-second. A human-chosen phrase does not satisfy this model simply because the box is checked.
Limits
The pool must be an integer from 2 to 1,000,000, and the guess rate must be positive and at most 10^18. Length is counted in Unicode code points; input is limited to 256 UTF-16 units. Huge times use scientific notation. Actual attack time depends on hashing, hardware, rate limits, attacker knowledge and other conditions.
Advice
Use unique passwords, a trustworthy password manager and available multifactor authentication. Length alone does not protect against phishing or a compromised device. Tool input processing uses no network requests or browser storage; the surrounding website can still load its normal assets. For private exploration, use fictional examples rather than an account password.
NIST: Password strength guidance
Frequently asked questions
Is entropy measured from my password?
No. The optional model assumes a known independent uniform generation process.
Does it check breaches?
No. It makes no breach API request.
Does no pattern mean safe?
No. The pattern list is deliberately limited.
Is the time a cracking prediction?
No. It is a hypothetical exhaustive-search calculation.