AddThisFeature

Password Strength Meter

Show whether a password is actually hard to guess, and how to fix it.

moderate User Accounts

What it adds

A live strength indicator based on guessability — length, common passwords, and terms drawn from the user's own details — with specific advice.

What your agent is told to do

5
  1. 1

    Score guessability, not character classes. 'P@ssw0rd1' satisfies every composition rule and is one of the first guesses any attacker makes.

  2. 2

    Penalise the user's own email, name, workspace and product name — those are the first things a targeted attacker tries.

  3. 3

    Give one concrete suggestion at a time, tied to the actual weakness. 'Add a symbol' is theatre; 'this is a common password' is useful.

  4. 4

    Evaluate entirely in the app. Never send a password, or anything derived from it that could be reversed, to a third-party service.

  5. 5

    Do not let the meter and the server disagree. If the server rejects something the meter called strong, the meter is lying — derive both from the same policy.

Edge cases it handles

6
  • The meter must be advisory unless server policy sets a real minimum; blocking on a subjective score frustrates people using password managers.
  • Very long passphrases must score well even without symbols or digits.
  • Pasted passwords from a manager must be scored the same as typed ones, and paste must not be blocked.
  • A large common-password list must not be shipped in a way that stalls the first keystroke — load it lazily or check server-side.
  • The score must be announced to assistive technology, and must not rely on colour alone to signal weakness.
  • Never log, echo, or include the password in error reports while scoring it.

Definition of done

8
  • Scoring accounts for length, common passwords, and user-specific terms.
  • Client feedback and server acceptance come from the same policy and never contradict each other.
  • No password data leaves the application.
  • Long passphrases score strongly without symbol requirements.
  • The strength level is conveyed by text as well as colour and is announced to screen readers.
  • Paste is allowed and scored identically to typing.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.