RootUtils

Password Breach Checker

Client-Side Secure

Check passwords against the Have I Been Pwned range API using k-anonymity. Hashes stay local for privacy.

Check your password safely
We use the Have I Been Pwned range API with k-anonymity. Only the first 5 chars of the SHA-1 hash leave your browser.

Is this tool broken?

Let us know if you found a bug or have a feature request.

Check if a password appears in known breaches using the Have I Been Pwned k-anonymity API. Only the first five characters of the SHA-1 hash are sent; the full password never leaves your browser.

  • Client-side hashing with optional padding for extra privacy.
  • Shows breach count and a short anonymous fingerprint.
  • Ideal for quick safety checks without account logins.