Verificador de Seguridad de Contraseña

Analyze password strength in real time

100% gratis. Funciona completamente en tu navegador: tus archivos y datos nunca salen de tu dispositivo y no se sube nada a ningún servidor.

Acerca de esta herramienta

Password strength is not about looking complicated - it is about how many guesses an attacker needs. That distinction explains why the familiar advice produces such weak results. "P@ssw0rd!" satisfies every complexity rule a website enforces: uppercase, lowercase, number, symbol, nine characters. It is also cracked in under a second, because cracking tools do not guess randomly. They start with leaked password lists containing billions of real passwords, then apply the exact substitutions humans reach for - @ for a, 0 for o, 1 for i, a capital at the front, a number and exclamation mark at the end. Every predictable pattern you add is a pattern the tool already knows. What genuinely resists attack is unpredictability multiplied by length, which is why a passphrase of four random words beats a short password with every symbol type. Analysis here runs entirely in your browser as you type - nothing is transmitted, logged or stored.

Flujo de trabajo

Protege una cuenta correctamente

  1. 1Generar una contraseñaLarga y aleatoria le gana a ingeniosa.Abrir
  2. 2Comprobar su seguridadMira cuánto tardaría en descifrarse.Estás aquí
  3. 3Medir la entropíaLas matemáticas detrás de lo adivinable que es realmente.Abrir

Cómo usar esta herramienta

  1. Type or paste a passwordThe assessment updates live as you type. Nothing leaves your browser at any point.
  2. Read the strength estimateIt considers length, character variety and recognisable patterns rather than just counting character types.
  3. Look at why it scored that wayA password marked weak despite meeting complexity rules usually contains a dictionary word or a predictable substitution.
  4. Lengthen rather than complicateAdding characters raises strength far more than adding another symbol to a short password.

Por qué usarla

  • Judges real resistance to guessing rather than whether a password satisfies arbitrary complexity rules.
  • Recognises the substitution patterns that make "complex-looking" passwords trivially weak.
  • Runs entirely in your browser - nothing transmitted, logged or stored.
  • Live feedback, so you can see what actually improves strength.
  • No account and no limit.

Usos comunes

  • Checking a password before using it on an account that matters.
  • Understanding why a password you thought was strong is not.
  • Comparing a complex short password against a longer passphrase.
  • Reviewing an old password to decide whether it needs replacing.
  • Demonstrating to colleagues why complexity rules alone do not produce strong passwords.

Consejos para mejores resultados

  • Length beats complexity every time. Sixteen characters of ordinary words outperforms eight characters of symbols.
  • Avoid anything derived from your own life - names, birthdays, pets, teams. All of it is guessable from public information.
  • Predictable substitutions add nothing. Cracking tools apply @ for a and 0 for o automatically, as their first move.
  • The strongest practical habit is a password manager with a unique random password per site, so no single breach spreads.
  • For the few passwords you must memorise, the Secure Passphrase Generator produces long, memorable, genuinely random options.

Errores a evitar

  • Believing a password is strong because a website accepted it. Complexity rules are a minimum, not a measure.
  • Using character substitution as the main defence, when it is the first thing attackers try.
  • Reusing a strong password across accounts, which makes its strength irrelevant after one breach.
  • Choosing short passwords because symbols are required, when the length is what actually matters.
  • Building passwords from personal details that appear on your own social media.
  • Pasting live production credentials into any online checker out of habit - even one that runs locally.

Preguntas frecuentes

Type or paste it above. The assessment updates live, considering length, variety and recognisable patterns - and nothing is transmitted.

Yes. No account, no limit, and no server involved at any point.

No. The analysis runs entirely in your browser as you type. Nothing is transmitted, logged or stored, which is the only acceptable design for a tool like this.

Being predictable. Short length, dictionary words, personal details, keyboard runs like qwerty, and the standard substitutions - @ for a, 0 for o. Cracking tools try all of those first, which is why they cost an attacker almost nothing.

Almost certainly because it is a dictionary word with predictable substitutions. "P@ssw0rd!" meets every complexity rule and falls in under a second, because the substitution pattern is the first thing any cracking tool applies.

At least 16 characters for anything that matters, and 20 or more for email and banking - email especially, since it can reset everything else. Each extra character multiplies the search space far more than another symbol does.

For anything you must memorise, yes. Four or five random words are long, easy to remember and hard to guess. For everything else, use a random password stored in a manager - you never have to type it.

It is safe by design, since nothing leaves your browser. But the better habit across every tool is to test something structurally similar rather than your exact live credentials - habits protect you where a given site's design might not.

La gente también busca

  • password strength checker free
  • how strong is my password
  • password security test
  • check password safety online
  • strong password examples
  • password entropy calculator
  • is my password compromised

Related guides