How to use
- 1Set the length (4–128) and choose uppercase, lowercase, numbers and symbols.
- 2Optionally exclude look-alike characters (I, l, 1, O, 0) or switch to passphrase mode.
- 3Five passwords are generated at once; check the strength meter.
- 4Copy the one you want and save it in your password manager.
What makes a password strong
Strength comes from length and randomness, measured in bits of entropy. A random password drawn from all 94 printable characters gets about 6.6 bits per character: 12 characters ≈ 79 bits, 16 characters ≈ 105 bits. Above roughly 80 bits a password is beyond realistic offline brute force; 100+ bits is excellent. NIST guidelines (SP 800-63B) now favor long passwords over forced complexity rules and periodic changes, and recommend allowing at least 64 characters.
Passwords vs passphrases
Passphrase mode picks random words from a built-in list of about 300 short English words, e.g. “ocean-tiger-paper-moon-river”. Each word from a 300-word list adds about 8.2 bits, so five words ≈ 41 bits and eight words ≈ 66 bits — easier to type and remember, but you need more words to match a random password. Use random passwords for anything stored in a password manager, passphrases for the few you must type by hand, like your manager’s master password (go for 7+ words).
Generated securely, never sent anywhere
Passwords are created with crypto.getRandomValues(), the browser’s cryptographically secure random number generator — not Math.random(). Everything happens on your device; nothing is transmitted or stored. Use a unique password for every account, store them in a password manager and turn on two-factor authentication: a reused password leaked in one breach is the most common way accounts get taken over.
Frequently asked questions
How long should my password be?
At least 12 characters for everyday accounts and 16+ for email, banking and password managers. With a password manager, length costs you nothing, so 20+ is fine.
How accurate is the crack-time estimate?
It is a rough estimate based on entropy and an assumed guessing rate for an offline attack. Real time depends on how the site stores passwords; treat it as a comparison, not a guarantee.
Is it safe to generate passwords online?
Here, yes: generation happens locally in your browser using a cryptographically secure generator, and no password ever leaves your device.
Why exclude ambiguous characters?
Characters like I, l, 1, O and 0 are easy to confuse when reading a password aloud or typing it from paper. Excluding them slightly reduces entropy, so add a character or two to compensate.
Not happy with the results?
Talk to Webin Agency about fast, SEO-friendly websites, e-commerce and Google Ads management.