Practical guide and verification
Choose the entropy model that matches generation
Length × log2(character pool) is appropriate only when each character is selected independently and uniformly from the stated pool. Human-created passwords and patterned substitutions do not satisfy that assumption, so do not label the theoretical pool result as measured unpredictability.
State the guessing-rate assumption
Crack-time estimates vary by many orders of magnitude depending on the hash/KDF, hardware, rate limiting and whether the attack is online or offline. Keep the selected guesses-per-second value visible beside the time estimate instead of presenting one universal crack time.
Separate random passphrases from human phrases
A passphrase assembled by uniformly selecting words from a known list can have calculable selection entropy. A memorable sentence invented by a person has different structure and should not inherit the random-word-list estimate simply because it contains the same number of words.
Do not paste real secrets unnecessarily
A browser-local checker can reduce server exposure, but sensitive production passwords still appear in the page, browser process and screen. Prefer evaluating a generated test value or the generation policy when the actual secret does not need to be inspected.
Use authentication controls beyond password strength
Password entropy does not replace unique credentials, secure storage, MFA, rate limiting, breach detection or recovery controls. Treat the calculator as one model for candidate unpredictability, not a complete account-security score.