Skip to main content

DEPRECATION WARNING

This package has been moved! Please install using pip install zxcvbn.

https://pypi.python.org/pypi/zxcvbn

Build Status

zxcvbn-python

A realistic password strength estimator.

This is a Python implementation of the library created by the team at Dropbox. The original library, written for JavaScript, can be found here.

While there may be other Python ports available, this one is the most up to date and is recommended by the original developers of zxcvbn at this time.

Features

  • Tested in Python versions 2.6-2.7, 3.3-3.6

  • Accepts user data to be added to the dictionaries that are tested against (name, birthdate, etc)

  • Gives a score to the password, from 0 (terrible) to 4 (great)

  • Provides feedback on the password and ways to improve it

  • Returns time estimates on how long it would take to guess the password in different situations

Installation

Install the package using pip: pip install zxcvbn-python

Usage

Pass a password as the first parameter, and a list of user-provided inputs as the user_inputs parameter (optional).

from zxcvbn import zxcvbn

results = zxcvbn('JohnSmith123', user_inputs=['John', 'Smith'])

print(results)

Output:

{
    'password': 'JohnSmith123',
    'score': 2,
    'guesses': 2567800,
    'guesses_log10': 6.409561194521849,
    'calc_time': datetime.timedelta(0, 0, 5204)
    'feedback': {
        'warning': '',
        'suggestions': [
            'Add another word or two. Uncommon words are better.',
            "Capitalization doesn't help very much"
        ]
    },
    'crack_times_display': {
        'offline_fast_hashing_1e10_per_second': 'less than a second'
        'offline_slow_hashing_1e4_per_second': '4 minutes',
        'online_no_throttling_10_per_second': '3 days',
        'online_throttling_100_per_hour': '3 years',
    },
    'crack_times_seconds': {
        'offline_fast_hashing_1e10_per_second': 0.00025678,
        'offline_slow_hashing_1e4_per_second': 256.78
        'online_no_throttling_10_per_second': 256780.0,
        'online_throttling_100_per_hour': 92440800.0,
    },
    'sequence': [{
        'matched_word': 'john',
        'rank': 2,
        'pattern': 'dictionary',
        'reversed': False,
        'token': 'John',
        'l33t': False,
        'uppercase_variations': 2,
        'i': 0,
        'guesses': 50,
        'l33t_variations': 1,
        'dictionary_name': 'male_names',
        'base_guesses': 2,
        'guesses_log10': 1.6989700043360185,
        'j': 3
    }, {
        'matched_word': 'smith123',
        'rank': 12789,
        'pattern': 'dictionary',
        'reversed': False,
        'token': 'Smith123',
        'l33t': False,
        'uppercase_variations': 2,
        'i': 4,
        'guesses': 25578,
        'l33t_variations': 1,
        'dictionary_name': 'passwords',
        'base_guesses': 12789,
        'guesses_log10': 4.407866583030775,
        'j': 11
    }],
}

Custom Ranked Dictionaries

In order to support more languages or just add password dictionaries of your own, there is a helper function you may use.

from zxcvbn.matching import add_frequency_lists

add_frequency_lists({
    'my_list': ['foo', 'bar'],
    'another_list': ['baz']
})

These lists will be added to the current ones, but you can also overwrite the current ones if you wish. The lists you add should be in order of how common the word is used with the most common words appearing first.

CLI

You an also use zxcvbn from the command line:

echo 'password' | zxcvbn --user-input <user-input> | jq

You can also execute the zxcvbn module:

echo 'password' | python -m zxcvbn --user-input <user-input> | jq

Contribute

License

The project is licensed under the MIT license.

Metadata

Release files for zxcvbn-python 4.4.24

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for zxcvbn-python 4.4.24
File Size Uploaded
zxcvbn-python-4.4.24.tar.gz 408.0 kB Details

Release files / zxcvbn-python-4.4.24.tar.gz

Download URL zxcvbn-python-4.4.24.tar.gz
Size 408.0 kB
Tags Source
SHA-256 checksum
How to use checksums
900b28cc5e96be4091d8778f19f222832890264e338765a1c1c09fca2db64b2d
BLAKE2b-256 checksum
How to use checksums
639cc3f90da63d6bd0e04948386bdf426212f1f8271d544615a5c8d0d03267ef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

4.4.24 This release

1 release file

4.4.23

1 release file

4.4.22

1 release file

4.4.21

1 release file

4.4.20

1 release file

4.4.19

1 release file

4.4.18

1 release file

4.4.17

2 release files

4.4.16

1 release file

4.4.15

1 release file

4.4.14

1 release file

4.4.13

1 release file

4.4.12

1 release file

4.4.11

1 release file

4.4.10

1 release file

4.4.9

1 release file

4.4.8

1 release file

4.4.7

1 release file

4.4.6

1 release file

4.4.5

1 release file

4.4.2

1 release file

4.4.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page