Password strength checker

I wanted a small tool that tells you how weak or strong a password is, and explains why, not just gives a pass or fail.

Python 3, and about two hours if you’re new to it.

The checker scores a password out of 5, based on three things: length, how many types of characters it mixes (lowercase, uppercase, numbers, symbols), and whether it’s on a list of extremely common passwords. Each rule adds points and a reason to a list, so the final answer always explains itself instead of just giving a number.

Here the code;

“””
Password Strength Checker
A small tool that scores a password and explains why it’s weak or strong.
“””
COMMON_PASSWORDS = {
“password”, “123456”, “12345678”, “qwerty”, “abc123”,
“password1”, “111111”, “letmein”, “admin”, “welcome”
}
def check_password(password):
score = 0
reasons = []
if len(password) >= 12: score += 2 reasons.append("Good length (12 or more characters).") elif len(password) >= 8: score += 1 reasons.append("Acceptable length (8-11 characters), but longer is stronger.") else: reasons.append("Too short. Aim for at least 12 characters.") has_lower = any(c.islower() for c in password) has_upper = any(c.isupper() for c in password) has_digit = any(c.isdigit() for c in password) has_symbol = any(not c.isalnum() for c in password) variety = sum([has_lower, has_upper, has_digit, has_symbol]) if variety >= 3: score += 2 reasons.append("Mixes multiple character types (letters, numbers, symbols).") elif variety == 2: score += 1 reasons.append("Uses only two character types. Add a symbol or a number.") else: reasons.append("Uses only one character type. This is easy to guess.") if password.lower() in COMMON_PASSWORDS: score = 0 reasons = ["This is one of the most commonly used passwords."] else: score += 1 return min(score, 5), reasons
if name == “main“:
pw = input(“Enter a password to check: “)
score, reasons = check_password(pw)
print(f”\nScore: {score}/5″)
for r in reasons:
print(f” – {r}”)

Run it with:

python3 password_checker.py

My first version scored Password1! as strong, because it technically had a capital letter, a number and a symbol. But it’s a well-known pattern attackers try first. I added a check against a list of common passwords that overrides the score entirely, even if the character rules look fine.

Meeting complexity rules (one uppercase, one number, one symbol) doesn’t make a password unpredictable. Length and avoiding common patterns matter more than ticking boxes.

Add a check for repeated characters (aaaa1111) or simple keyboard patterns (qwerty123), both of which pass the character-variety rule but are still easy to guess.

The full code is on GitHub.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *