Dev.to
7/18/2026

Building a password strength checker with ML classification and breach detection
Original: I Built a Password Strength Checker That Actually Works (Here's Why Most Fail)
Short summary
A developer built a password strength checker combining a Random Forest classifier (93.3% accuracy on 28 features including entropy, bigram entropy, and keyboard-walk detection) with Have I Been Pwned breach detection. The key insight is that breach status overrides all structural metrics—a password like "Tr0ub4dor&3" scores Strong on ML but is actually compromised across 3,196 breaches. The system aligns with NIST SP 800-63B requirements that most checkers ignore.
- •Random Forest classifier trained on 150 passwords across 6 character-composition categories achieves 93.3% accuracy
- •HIBP breach detection overrides ML structural scoring—empirical compromise status is ground truth
- •Aligns with NIST SP 800-63B which requires breach checking that most password checkers skip
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



