Local analysis
The estimator runs in this tab. The password is kept only in temporary component memory and is not logged, saved, placed in a URL, or submitted to FunPass.
Privacy by design
The FunPass analyzer runs entirely in your browser. It does not save, submit, log, or transmit what you type. The optional breach check sends only a partial hash after you request it.
Methodology and threat model
FunPass explains what it measures, what leaves the device, and where its conclusions stop. A security tool should make its limitations visible.
The estimator runs in this tab. The password is kept only in temporary component memory and is not logged, saved, placed in a URL, or submitted to FunPass.
Scores use zxcvbn-ts to model common passwords, dictionary terms, dates, repeats, keyboard paths, sequences, and likely guesses. It is an estimate—not a guarantee.
Only after you press the breach-check button, the browser sends a five-character SHA-1 prefix to HIBP. Response padding is requested and matching finishes locally.
No password score prevents phishing, malware, insecure server storage, or account recovery abuse. Unique passwords, MFA, passkeys, and secure services work together.
LIVE PRIVACY CONTRACT