zxcvbn
Decision gist · record as of 2026-08-14
Yes. zxcvbn is a well-maintained, dependency-free library recommended by its original creators, with no known vulnerabilities, permissive licensing, and broad Python version support. Install it if you need realistic password strength estimation with actionable feedback rather than simple regex or entropy rules.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with no runtime dependencies.
- Actively maintained as of 2025-02-19 with recent commits and 715 repository stars; tested across Python 3.8–3.13.
License · maintenance · safety
MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
last release 2025-02-19 (541 days) · last repo commit 2026-04-13 · 715 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,840,471 downloads/mo, #2,025 on PyPI
Alternatives
Verify before relying
pip install zxcvbn
from zxcvbn import zxcvbn
results = zxcvbn('JohnSmith123', user_inputs=['John', 'Smith'])
print(results['score'], results['feedback'])- Whether performance remains acceptable when max_length is set significantly above the default 72 in production environments
What it is and what it does
zxcvbn is a Python port of Dropbox's realistic password strength estimator. It analyzes a password against multiple pattern-matching techniques—dictionary words, common sequences, repeated characters, keyboard patterns—and returns a numeric score (0–4) along with specific feedback on weaknesses and estimated crack times under different attack scenarios (online throttled, online unthrottled, offline slow hashing, offline fast hashing). You can supply user-provided data like names or birthdates to be checked against the password, and optionally customize the maximum password length or add custom frequency dictionaries for additional languages or domain-specific word lists.
The package is recommended by the original Dropbox developers and is the most actively maintained Python implementation. It has no external runtime dependencies, making it straightforward to integrate into authentication systems, password validators, or user-facing password-creation interfaces. The library also exposes a command-line interface for scripting and testing.
Use it for
- Validate user passwords during account creation or password-reset flows with real-time feedback on strength.
- Implement server-side password policy enforcement that rejects weak passwords before storing them.
- Display crack-time estimates to users to help them understand the security implications of their password choice.
- Add custom dictionaries to detect common passwords or phrases specific to your organization or language.
- Analyze password datasets to identify weak patterns and inform security training or policy updates.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
zxcvbn is a well-maintained, dependency-free library recommended by its original creators, with no known vulnerabilities, permissive licensing, and broad Python version support. Install it if you need realistic password strength estimation with actionable feedback rather than simple regex or entropy rules.
Install
zxcvbn on PyPI
Before you install
Low install friction with no runtime dependencies. Actively maintained as of 2025-02-19 with recent commits and 715 repository stars; tested across Python 3.8–3.13.
License in practice
MIT license permits free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
Quickstart
pip install zxcvbn
from zxcvbn import zxcvbn
results = zxcvbn('JohnSmith123', user_inputs=['John', 'Smith'])
print(results['score'], results['feedback'])
Verify before relying
- Whether performance remains acceptable when max_length is set significantly above the default 72 in production environments
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 541 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,840,471 / month, #2,025 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software Development :: Libraries :: Python Modules |
Evidence: zxcvbn-4.5.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “password strength estimator”
- zxcvbnEstimates password strength by analyzing patterns, common words, and…
- django-zxcvbn-password-validatorA Django password validator that uses pattern matching and dictionary…
- password-strengthEvaluates password strength and validates passwords against…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also django-zxcvbn-password-validator · types-zxcvbn · password-strength · pyspellchecker · properscoring · diceware · xkcdpass · mnemonic · sklearn-crfsuite · better-profanity