Private browser-based security tool

Nerine - Password Security Checker

Check password security with a clean strength analysis and a private breach lookup. Nerine helps you understand whether a password is weak, predictable, or already exposed in known data breaches.

Runs in your browser No full password upload HIBP k-anonymity check
Security tip

Enable MFA for important accounts, even when your password is strong.

Password analysis

Check a password

Enter a password to see its strength score, risk signals, and public breach exposure status.

Strength meter Password strength will appear here
Risk score -- Type a password to start.
Password anatomy
  • MFA baselineType first
  • No-MFA baselineType first
  • Known breachType first
  • Pattern riskType first
  • Character varietyType first
  • Reuse reminderType first
Result explanation

Nerine will explain the local strength signal and breach signal after you type a password.

Password copied successfully.
Privacy note: password strength is analyzed in your browser. For breach checks, Nerine uses the Have I Been Pwned password API with k-anonymity, so your full password is not sent.
  • Strength analysis runs locally.
  • SHA-1 hashing happens in your browser.
  • Only the first five hash characters are sent to HIBP.
  • Final matching happens locally in this page.
Version: 2.4.2

Password security guide

Check password security before you reuse it anywhere

This password security guide is inspired by public guidance from the Center for Internet Security (CIS) Password Policy Guide and CIS Controls recommendations for unique passwords, MFA, and minimum password length. Nerine uses these principles as educational guidance, not as a formal compliance certification.

Many passwords look strong at first glance, but security depends on more than symbols and uppercase letters. A good password should be long, hard to guess, unique for one account, protected with MFA whenever possible, and not already exposed in a public breach. Nerine combines local password analysis with a breached password checker so you can make a better decision before using a password on email, banking, social media, work accounts, or cloud services.

Breach checking is a separate signal. Nerine hashes the password in your browser, sends only the first five SHA-1 hash characters to Have I Been Pwned, and compares the returned suffix list locally. This k-anonymity approach checks known exposure without sending the complete password.

Use the result as a practical risk signal: prefer longer passphrases, enable MFA for sensitive accounts, and replace any password that appears in known breach data.

Anatomy guide

What Password Anatomy Means

Password anatomy explains the signals Nerine uses to summarize risk. Some signals are checked locally, while reuse is shown as guidance because Nerine never compares your password with other passwords you use.

MFA baseline
Checks whether the password reaches the 8-character baseline commonly used when MFA is enabled.
No-MFA baseline
Checks whether the password reaches the 14-character baseline recommended for accounts without MFA.
Known breach
Shows whether the password appears in public breach data after running the HIBP check.
Pattern risk
Flags obvious risks such as common words, keyboard patterns, repeated characters, sequential numbers, or year-like numbers.
Character variety
Shows how varied the characters are. Variety can help, but length, uniqueness, MFA, pattern risk, and breach exposure are more important signals.
Reuse reminder
Reminds you to use the password for one account only. Nerine cannot verify reuse because it does not know your other passwords.

FAQ

Password Security Checker Questions

Does Nerine store my password?

No. Nerine does not store, record, or log the password you type. Strength analysis runs in the browser, and breach checking uses a partial hash lookup.

Is a strong password always safe?

Not always. A password can be long and complex but still unsafe if it has already appeared in a data breach. That is why breach checking is useful alongside strength checking.

Why is the breach check limited to 25 characters?

This tool keeps the current breach-checking behavior lightweight and focused. You can still use the strength meter for longer passwords, while the breach lookup follows the existing tool limit.

How can I contact Mediaagni Tools?

For feedback, questions, or suggestions about Nerine, visit Contact Us. If this tool is helpful and you want to support development, you can support the creator on Saweria.