Password Generator

A strong password is long and random. The generator creates one right in your browser, without sending it to a server.

The password generator on sites.reviews creates cryptographically strong passwords directly in your browser — no data is sent to any server, no registration required. The entire generation process runs locally: not a single character leaves your device.

How to use the generator

The tool works in one click. Adjust the settings to match your needs:

  1. Set the password length — we recommend at least 16 characters.
  2. Enable the character sets you need: uppercase letters, digits, special characters (!@#$%^&*).
  3. Click "Generate" — your password appears instantly.
  4. Copy it to your password manager with one click.

No forms, no accounts. Click again to get a fresh password.

What makes a password strong

A weak password can be cracked in seconds. A strong one — in millennia. Here are the key criteria:

  • Length of 12+ characters — every additional character exponentially increases brute-force time.
  • Mixed case — uppercase and lowercase letters combined.
  • Digits and special characters — expand the total space of possible combinations.
  • No dictionary words — a random sequence, not "password123".
  • Unique for every service — a leak on one site won't compromise your other accounts.
  • Stored in a password manager — Bitwarden, KeePass or similar: nothing to memorize.

Frequently asked questions

Is the generated password sent to the server?

No. Generation runs entirely on the client side using the browser's crypto.getRandomValues() API. The server receives no data — not the password, not the settings. You can verify this yourself in your browser's developer tools: the Network tab will show zero requests at the moment of generation.

What password length is considered safe?

The minimum is 12 characters for low-stakes accounts. For email, banking, and primary accounts, use 16 to 20 characters with special characters enabled. Brute-forcing a 20-character password drawn from the full character set would take an astronomical amount of time even with modern hardware.

Why use a unique password on every site?

When a site's database leaks — and it happens regularly — attackers automatically test that same login/password pair across hundreds of other services. This technique is called credential stuffing. A unique password for every site completely neutralises this attack vector.

How do I remember all these passwords?

You don't have to. Use a password manager: it stores all your passwords in encrypted form and fills them in automatically. You only need to remember one master password — which can be a long but memorable passphrase.

See also other tools on the site.