How entropy is calculated
N × log₂(wordlist size). Each extra word multiplies the search space. Separator choice, capitalisation mode, and l33t substitutions add bonus bits.
Length × log₂(charset size). All 4 character sets enabled gives log₂(94) ≈ 6.55 bits per character. 20 chars = 131 bits.
Sum of log₂(pool size) per slot. Noun and adjective slots use the full word list, boosting entropy far above small grammar pools alone.
Crack time assumes 100 billion guesses/second — an offline GPU cluster attack. Online attacks are orders of magnitude slower.
Frequently asked questions
Are my passwords ever sent to a server?
When you use this page, generation happens entirely in your browser using crypto.getRandomValues() and never leaves your device. The REST API generates passwords at Cloudflare's edge on request and does not log or store them, but a password sent to the API by definition travels over the network to get a response — for maximum privacy, use the browser UI above.
What's the difference between the generation model and brute-force model bits?
The generation model assumes the attacker knows your wordlist and word count — the conservative, cryptographic lower bound. The brute-force model assumes the attacker tries all possible character combinations, which is what most online password meters show. Reality sits between the two; use the generation model as your benchmark.
Why SHA-256 as the crack-time baseline instead of MD5 or bcrypt?
MD5, SHA-1, NTLM, and LM are cryptographically broken and crackable at 100 billion+ guesses/second, so using them would understate real risk. Slow hashes like bcrypt, Argon2, or scrypt (100K–1M guesses/second) are what's actually recommended for storing passwords, but assuming every site uses them would overstate your safety. SHA-256 at roughly 8 billion guesses/second on a GPU cluster is the responsible middle-ground baseline used here.
How big is the bundled wordlist, and can it be upgraded?
The bundled wordlist has 1,246 words (≈10.3 bits/word). It can be swapped for the EFF Large Wordlist (7,776 words, ≈12.9 bits/word) for significantly stronger passphrases — see the project's README for the one-command upgrade.
All three generators are available via a REST API on Cloudflare's edge. All generation is edge-side using Cloudflare Pages Functions. No data is logged or stored.
/api/generate{
"type": "word" | "char" | "phrase",
"count": 1–10,
// Word & phrase options
"wordCount": 2–10,
"separator": "-" | "." | "_" | " " | "~" | "!" | "@" | … | null (random),
"capMode": "first" | "last" | "random" | "vowel" | "all" | "none",
"injectNum": true | false,
"leet": true | false,
// Character options
"length": 8–64,
"lower": true | false,
"upper": true | false,
"numbers": true | false,
"special": true | false
}
{
"passwords": [
{
"value": "C0balt-Forg3d-7Leaps-Swiftly",
"bits": 78.4,
"strength": { "label": "Good", "level": 2 },
"time": "centuries",
"warnings": [],
"type": "word"
}
],
"meta": { "type": "word", "count": 1, "generatedAt": "2026-04-15T10:30:00Z" }
}
curl -X POST https://pwd.insecure.co.nz/api/generate \
-H "Content-Type: application/json" \
-d '{"type":"word","wordCount":6,"capMode":"random","leet":true,"count":3}'