Security · Free tool

Password & Account Security Checker

How strong is your password, has it leaked, and are your Gmail, WhatsApp and mobile-money accounts locked down? Nothing you type leaves your browser.

How strong is it?

Checked in your browser as you type. Nothing you enter here is sent, stored or logged — not even to Hurbad.

Type a password to see how it holds up.

Has it appeared in a data breach?

Optional. Your browser hashes the password (SHA-1) and sends only the first 5 characters of the hash to Have I Been Pwned, which replies with every match for that prefix; the comparison happens here. The password and its full hash never leave this page.

Need a good one? Use a passphrase.

Random words from a 512-word list, drawn by your browser's secure random generator. Easy to type, hard to guess.

…
≈ 45 bits

Change a word or two, add a symbol you will remember, and use it for one account only — a password manager can hold the rest.

Account security checklist: 0 / 10

The accounts that matter most, with the settings that stop most takeovers. Signed out: ticks stay in this browser. Sign in to keep them and see the score on your dashboard.

  1. Your email resets every other password. Lose it and you lose everything.

    1. Open myaccount.google.com → Security → 2-Step Verification.
    2. Add your phone or, better, the Google Authenticator app.
    3. Save the backup codes somewhere safe (not in Gmail).
    4. Check 'Your devices' and sign out of anything you do not recognise.
  2. Without recovery details a locked account is gone for good.

    1. Security → Recovery phone and Recovery email.
    2. Use a number you will still have next year.
    3. Never use the same recovery email as the account itself.
  3. Hijacked Facebook accounts are used to scam your friends and family.

    1. Settings → Accounts Center → Password and security → Two-factor authentication.
    2. Choose an authenticator app over SMS where you can.
    3. Turn on login alerts and review 'Where you're logged in'.
  4. A SIM swap or a stolen code otherwise moves your WhatsApp to a stranger's phone.

    1. Settings → Account → Two-step verification → Turn on.
    2. Pick a 6-digit PIN nobody could guess (not your birthday).
    3. Add the recovery email in case you forget the PIN.
    4. Never share the 6-digit registration code WhatsApp sends you — not even with 'support'.
  5. Instagram accounts are stolen and sold; the reset goes through your email and phone.

    1. Settings → Accounts Center → Password and security → Two-factor authentication.
    2. Use an authenticator app; save the backup codes.
    3. Check 'Login activity' for devices you do not know.
  6. Same story: a stolen account is used for scams under your name.

    1. Profile → Menu → Settings and privacy → Security and permissions → 2-step verification.
    2. Turn on at least two methods (authenticator app + email).
    3. Review 'Your devices' and log out of unknown ones.
  7. The PIN is the money. Most losses come from a PIN told to a 'helpful' caller.

    1. Use a PIN that is not your birthday, phone digits or 1234.
    2. Never tell the PIN to anyone — no operator, agent or 'bank staff' will ever ask for it.
    3. Do not reuse the PIN for your phone lock or SIM.
    4. If a caller asks you to dial codes or confirm a transfer, hang up and call the official number yourself.
  8. A lost unlocked phone is every account at once — email, banking, WhatsApp.

    1. Set a 6-digit PIN or a real passphrase; fingerprint or face is fine on top of it.
    2. Set auto-lock to one minute or less.
    3. Turn on 'Find my device' so a lost phone can be wiped remotely.
    4. Keep the operating system updated — updates are mostly security fixes.
  9. Reused passwords are how one leaked site becomes every site.

    1. Pick one manager (Bitwarden is free and open source; the built-in Google or Apple one also works).
    2. Let it generate a different password for every site.
    3. Protect the manager itself with a long passphrase and 2FA.
  10. Most account takeovers start with one convincing message, not with hacking.

    1. Urgency, threats or prizes are the tell. Slow down.
    2. Check the sender's real address and hover over links before clicking.
    3. Never type a password into a page you reached from a message — go to the site yourself.
    4. When in doubt, ask someone or ignore it; a real bank or school will not mind.