Skip to content

Password Strength Analyser — TypeScript source

Estimate password strength with zxcvbn - realistic dictionary and pattern cracking with crack-time estimates and improvement suggestions. Runs entirely in your browser.

This is the TypeScript implementation — the same logic the interactive tool runs, in a shareable, citable form.

// Password strength analysis backed by `zxcvbn` (dictionary + pattern
// estimation). The unit-test surface for the Password Strength Analyser tool.

import zxcvbn from 'zxcvbn';

export interface PasswordAnalysis {
  score: 0 | 1 | 2 | 3 | 4;
  label: string;
  guessesLog10: number;
  crackTimeOfflineFast: string;
  crackTimeOnline: string;
  warning: string;
  suggestions: string[];
}

const LABELS = ['Very weak', 'Weak', 'Fair', 'Good', 'Strong'] as const;

/** Analyse a password's strength. `userInputs` seeds the dictionary (e.g. username, site). */
export function analysePassword(password: string, userInputs: string[] = []): PasswordAnalysis {
  const r = zxcvbn(password, userInputs);
  return {
    score: r.score,
    label: LABELS[r.score],
    guessesLog10: r.guesses_log10,
    crackTimeOfflineFast: r.crack_times_display.offline_fast_hashing_1e10_per_second,
    crackTimeOnline: r.crack_times_display.online_no_throttling_10_per_second,
    warning: r.feedback.warning,
    suggestions: r.feedback.suggestions,
  };
}

Also available in 13 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →