Skip to content

Password Strength Analyser — Go source

Estimate password strength with zxcvbn - realistic dictionary and pattern cracking with crack-time estimates and improvement suggestions. Runs entirely in your browser.

This is the Go implementation — the same logic the interactive tool runs, in a shareable, citable form.

// Package pwstrength is the Go twin of CosmoDev's src/lib/password-strength.ts
// (dual source: the web lib is TypeScript, the CLI lib is Go). Both wrap zxcvbn
// (TS: the `zxcvbn` npm package; Go: github.com/nbutton23/zxcvbn-go), so the
// score (0–4) is identical for the same password — the primary lock-step field.
//
// Parity note: the JS zxcvbn exposes four crack-time fields
// (online/offline × throttled/fast); the Go port exposes a single
// CrackTimeDisplay, so the crack-time strings are not field-for-field identical
// to the web tool. The score and entropy are the lock-step contract.
package pwstrength

import (
	"github.com/nbutton23/zxcvbn-go"
)

// Result is the strength breakdown. Score mirrors the web tool's 0–4 exactly.
type Result struct {
	Score            int     // 0 (worst) … 4 (best)
	Label            string  // human label
	Entropy          float64 // bits of entropy
	CrackTimeDisplay string  // single display string (Go port has one; JS has four)
}

var labels = []string{"Very weak", "Weak", "Fair", "Good", "Strong"}

// Analyse scores a password with zxcvbn. userInputs seeds the dictionary (e.g.
// username, site). It is the Go twin of analysePassword() in password-strength.ts.
func Analyse(password string, userInputs []string) Result {
	r := zxcvbn.PasswordStrength(password, userInputs)
	score := r.Score
	if score < 0 {
		score = 0
	} else if score > 4 {
		score = 4
	}
	return Result{
		Score:            score,
		Label:            labels[score],
		Entropy:          r.Entropy,
		CrackTimeDisplay: r.CrackTimeDisplay,
	}
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →