Password strength checker

Need a new one? Generate a password

Transparency

Your password never leaves this page. It is analysed in your browser by the scripts listed below, and by nothing else.

Enforced by your browser
This page's Content Security Policy allows a single destination, the site's audience measurement (connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'), so even a bug could not send your password anywhere but to that server, which belongs to R-no. You can read the policy at the top of the page source.
Audience measurement
Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
  • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
    SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
  • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
What is stored
No cookie, and nothing in the address. The password is never stored, and the field is emptied when you leave the page. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives your password.
Code that runs here
  • app.js: the strength checker, written for R-no Toolbox. Not minified. 7.8 kB
    SHA-256 58a9294387fe6fc8d3c399d1df929f040f21b802233184972f4043839a570de1
  • zxcvbn.js: the zxcvbn-ts strength estimator (core 4.2.0), with its common, English and French dictionaries and its English and French messages. MIT License. Not minified. 2.4 MB
    SHA-256 53702cbd5708ffaf67d6af89dc85740abf62ef9d342c834501c7319d34028a3c
  • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 6.7 kB
    SHA-256 e7e8f4d1500168b0fc1d8da8be7997ef59a0400bcf38d892568c0288d78587e2
  • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
    SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
  • zxcvbn.LICENSES.txt: every package bundled in zxcvbn.js, with its version and full license. The English and French word lists come from OpenSubtitles 2024 via OPUS (ODC-BY).
Where zxcvbn.js comes from
It is built from pinned npm packages, whose integrity npm checks against the lockfile. On every deployment it is rebuilt from scratch and compared byte for byte with the file served here; the deployment stops if they differ.
Check it yourself
Download a file and compare its fingerprint with the one above:
curl -s https://r-no.fr/passwords/strength/app.js | shasum -a 256
Limits
This is an estimate, not a guarantee. It recognises common passwords, English and French words, names, keyboard patterns, dates, sequences and repetitions, but not your personal details. Only the first 64 characters are analysed. It does not check whether the password appeared in a data breach: that would mean sending something about it over the network.