This meter uses a compact local model inspired by password-cracking strategies. Unlike a simple checklist, it can recognize that a familiar word with a capital letter, number, and symbol may still be easy to guess. It checks a focused list of common passwords and words plus dates, repeats, sequences, keyboard paths, and common substitutions. It cannot protect against phishing, malware, reuse, or a breached service.
Crack time depends heavily on how a site stores passwords. The slow-hash figure assumes 10,000 guesses per second, while the fast-hash figure assumes 10 billion. Treat both as comparisons, not promises. For an account you care about, use a unique password from a password manager and enable multi-factor authentication.