DecodeLabs Industrial Training Kit — Project 1 (Defensive Phase)
A pure-Python command-line tool that evaluates whether a password is Weak, Medium, or Strong based on length, character variety, entropy, and whether it appears in a list of common/leaked passwords. No external dependencies required.
- ✅ Length check (minimum 8 characters)
- ✅ Character variety checks: lowercase, uppercase, digits, symbols
- ✅ Common / leaked password detection (constant-time comparison)
- ✅ Simple entropy (search-space) estimate in bits
- ✅ Clear Weak / Medium / Strong verdict with actionable suggestions
- ✅ Hidden password input (won't echo to terminal)
- ✅ Unit tested
=== DecodeLabs Password Strength Checker ===
(Input is hidden while typing. Press Ctrl+C to quit.)
Enter a password to check:
----------------------------------------
Strength : 🟢 Strong
Score : 5/5
Est. Entropy : 91.76 bits
Suggestions : None — this password meets all criteria!
----------------------------------------
- Python 3.7+
git clone https://github.com/<your-username>/password-strength-checker.git
cd password-strength-checkerNo pip install needed — it only uses the Python standard library.
python password_checker.pyType a password when prompted. Your input is hidden as you type.
Press Ctrl+C to exit.
python -m unittest test_password_checker.py -v| Check | Logic |
|---|---|
| Length | Passwords under 8 characters fail immediately (exponential brute-force risk) |
| Variety | Checks for lowercase, uppercase, digits, and symbols using Python's str methods |
| Leaked password | Compares (case-insensitively, in constant time via hmac.compare_digest) against a small sample list of known common passwords |
| Entropy | Estimates bits of entropy as length × log2(character_pool_size) |
| Verdict | Combines all of the above into a Weak / Medium / Strong classification |
- Load a much larger breached-password list (e.g. via the Have I Been Pwned API)
- Add a graphical or web front-end
- Support password generation in addition to checking
- Add zxcvbn-style pattern detection (keyboard walks, repeated chars, etc.)
MIT — see LICENSE.
Built as part of the DecodeLabs Cyber Security Industrial Training Kit (Project 1 — Batch 2026).