Offline ML-powered password strength evaluation using a trained Random Forest model.
Project description
passeval
Offline ML-powered password strength evaluation for Python developers.
passeval uses a trained Random Forest classifier to score passwords as Weak, Medium, or Strong — with confidence scores and actionable feedback. Everything runs locally: no API calls, no servers, no internet required.
Installation
pip install passeval
Quick Start
from passeval import evaluate_password
result = evaluate_password("Monkey2024!")
print(result)
Output:
{
"score": 0,
"label": "Weak",
"confidence": 1.0,
"features": {
"length": 11,
"entropy": 3.2776,
"num_upper": 1,
"num_digits": 4,
"num_special": 1
},
"feedback": [
"Longer passwords are significantly harder to crack",
"Avoid predictable patterns like years or repeated digits"
]
}
API Reference
evaluate_password(password: str) → dict
Evaluates a password and returns a structured result.
| Key | Type | Description |
|---|---|---|
score |
int |
Numeric strength: 0 = Weak, 1 = Medium, 2 = Strong |
label |
str |
Human-readable label matching the score |
confidence |
float |
Model probability for the predicted class (0.0 – 1.0) |
features |
dict |
Key statistics extracted from the password |
feedback |
list |
Actionable suggestions; empty list means no issues found |
Raises:
TypeError– if input is not a stringValueError– if input is an empty string
extract_features(password: str) → dict
Returns all 10 raw statistical features used by the model.
from passeval import extract_features
extract_features("Monkey2024!")
# {
# 'length': 11, 'num_upper': 1, 'num_lower': 6,
# 'num_digits': 4, 'num_special': 1, 'entropy': 3.2776,
# 'unique_chars': 10, 'has_upper': 1, 'has_digit': 1, 'has_special': 1
# }
More Examples
from passeval import evaluate_password
# Weak password
r = evaluate_password("hunter2")
print(r["label"]) # Weak
print(r["feedback"]) # ['Use at least 8 characters', 'Add at least one uppercase letter', ...]
# Medium password
r = evaluate_password("Password1")
print(r["label"]) # Medium
print(r["confidence"]) # 0.86
# Strong password
r = evaluate_password("xK9#mP2$vL8@")
print(r["label"]) # Strong
print(r["confidence"]) # 1.0
print(r["feedback"]) # []
How It Works
Feature Extraction
passeval computes 10 statistical features from each password:
| Feature | Description |
|---|---|
length |
Total number of characters |
num_upper |
Count of uppercase letters |
num_lower |
Count of lowercase letters |
num_digits |
Count of digit characters |
num_special |
Count of non-alphanumeric characters |
entropy |
Shannon entropy (bits per character) |
unique_chars |
Number of distinct characters used |
has_upper |
Boolean: contains at least one uppercase |
has_digit |
Boolean: contains at least one digit |
has_special |
Boolean: contains at least one special char |
ML Model
A Random Forest classifier was trained on a labeled password dataset. It learns non-linear relationships between these features and password strength — going beyond simple rule matching.
predict_proba() is used to surface a confidence score alongside the predicted class, giving callers a sense of how certain the model is.
ML vs Rule-Based: Why Not zxcvbn?
zxcvbn is a well-known rule-based estimator that checks passwords against wordlists, keyboard patterns, and dates. It is excellent for its use case, but it has some differences from passeval:
| Feature | passeval (ML) | zxcvbn (rule-based) |
|---|---|---|
| Approach | Random Forest classifier | Pattern + dictionary rules |
| Scores derived from | Learned statistical patterns | Hardcoded heuristics |
| Confidence score | Yes (model probability) | No |
| Customisable training data | Yes (retrain on your data) | No |
| Wordlist dependency | None | Bundled ~30k word list |
| Generalises to novel patterns | Yes (via feature stats) | Limited to known patterns |
| Fully offline | Yes | Yes |
Both tools have value. passeval is better suited when you want ML-derived confidence scores, a trainable model, or a smaller dependency footprint.
Offline Advantage
passeval ships the trained model file (passmeter_model.pkl) inside the package itself. Once installed via pip, it works in:
- Air-gapped servers and secure environments
- CI/CD pipelines with no outbound network access
- Embedded systems and edge deployments
- Any environment where calling an external API is undesirable
No credentials, no rate limits, no latency from a remote service.
License
MIT — see LICENSE.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file passeval-0.1.2.tar.gz.
File metadata
- Download URL: passeval-0.1.2.tar.gz
- Upload date:
- Size: 1.8 MB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2b8eaf17b3a68f7c5e5562f4a1c7038bd015c0dcc29b9d675387ae802e784d60
|
|
| MD5 |
3da46e5aeaaa570ea30d58f1d3293a5a
|
|
| BLAKE2b-256 |
d16b1f45be4f605294d9b6ead73d183b7637e55c904a0784333d26fed0c0e60f
|
File details
Details for the file passeval-0.1.2-py3-none-any.whl.
File metadata
- Download URL: passeval-0.1.2-py3-none-any.whl
- Upload date:
- Size: 1.8 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4dca2257114c0bd342b86d234f654624f07b1acc9677d52b853345663f0dda93
|
|
| MD5 |
ab7d07edcc7f859c493cdf902869f240
|
|
| BLAKE2b-256 |
44bf64e0353c0a5a4115e1cc3d0d55b5aa60425fd3723e3e50f4fd782a1fb6fd
|