Utility

Password Reuse Checker

A password reuse checker takes a list of passwords and finds the ones that are effectively the same: exact repeats, repeats differing only in case, and families like Summer2023 and Summer2024 that share a base word. Everything runs in the browser and passwords are shown masked, with a short SHA-256 prefix for reference.

Last reviewed by the Radiatus Cloud team

Password Reuse Risk Checker

Detect reused passwords across your accounts with client-side hash-based analysis

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Why near-duplicates count as reuse

Credential stuffing takes a username and password leaked from one site and tries them on hundreds of others. The tools that do it, and the wordlists behind them, apply mangling rules automatically: capitalise the first letter, append a year, swap a trailing exclamation mark for a one. To an attacker holding Summer2023!, the password summer2024 is not a new password, it is the first guess. The checker groups passwords by their base word after stripping case, punctuation and trailing digits or years, and reports each group as a family.

What the report shows

  • Exact duplicates, with the line numbers that match.
  • Pattern families, where the base word is shared and only the suffix differs.
  • Entries on a short list of the most common passwords, or under eight characters.
  • Each password masked to first and last character, its length, and the first twelve hex characters of its SHA-256 hash, so two lines can be compared without displaying them.

Where this fits with current guidance

NIST Special Publication 800-63B, the reference most corporate policies now follow, dropped mandatory periodic rotation because it produces exactly the year-bumped families this tool detects. It recommends instead: screen new passwords against breach lists, require length over composition rules, and rotate only on evidence of compromise. If your list shows families, the fix is a password manager generating unrelated strings, not a stricter rotation schedule.

A worked run

Six lines: P@ssword1, Welcome123, welcome123, Summer2023!, Summer2024! and x9Tq-vLm2#Rp. The report finds one case-only duplicate pair, one family of two, one common-list hit and rates four of six as reused or related. The last entry is the only one that would survive a stuffing attack, and it is the only one nobody could remember, which is the argument for a manager in one line.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Leaks Checker — Check whether a password appears in known breach corpora, using k-anonymity so the password never leaves your device.
  • Passphrase Generator — Generate strong, memorable passphrases from random words (diceware-style) with custom word count, separators, capitalization and numbers. Uses secure RNG. Private.
  • Credential Stuffing Risk — A new tool extracted from the codebase.

Frequently Asked Questions

Is it safe to paste real passwords here?

The page does no network requests with the data; grouping and hashing run in JavaScript in your browser. Even so, the sensible use is auditing your own list from a password manager export, then closing the tab.

What counts as a pattern family?

Passwords that are identical after lowercasing, removing punctuation, and dropping a trailing year or run of digits, provided the remaining base is at least four characters. Summer2023!, summer2024 and SUMMER99 are one family.

Why does the checker not tell me whether a password has been breached?

That needs a lookup against a breach corpus, which means sending at least a hash prefix to a service. This tool is deliberately offline. Use the password leaks checker, which implements the k-anonymity lookup, for that.

Should I rotate passwords every 90 days?

Not according to NIST 800-63B or the UK NCSC. Forced rotation produces predictable increments. Rotate on compromise, use unique passwords everywhere, and turn on multi-factor authentication.

What does the SHA-256 prefix column mean?

The first twelve hex characters of the password's hash. Two lines with the same prefix are the same password. It is shown so you can identify entries without reading the masked text aloud in a screen share.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.