PassFortress is a CLI toolkit that evaluates password strength across 13 distinct security dimensions, returning a detailed per-criterion breakdown, a numeric score (0β100), estimated entropy in bits, and actionable improvement suggestions all from a single command.
- About the Project
- Architecture
- Installation
- Verify Installation
- Usage
- Development
- Contributing
- License
- Disclaimer
SecureArmor was built around the idea that password feedback should be specific, honest, and actionable not just a colour-coded "weak / strong" bar. Under the hood it combines multiple heuristics into a single 0β100 score, with each criterion carrying independent weight:
- Multi-dimensional scoring 13 criteria covering length, character class presence, variety, uniqueness, entropy, common-password detection, and keyboard-pattern recognition.
- Entropy estimation a blended pool-size / Shannon model that quantifies true unpredictability, not just rule compliance.
- Leet-speak normalisation common substitutions (
@βa,0βo,$βs, β¦) are decoded before the common-password check, soP@$$w0rdis flagged just likePassword. - Safe by default the raw password is never stored or logged; only a masked form (
M*******!) is kept in the result object. - Machine-readable output every command supports
--jsonfor NDJSON-compatible output suitable for scripting, CI pipelines, and downstream tooling. - Batch support pipe a newline-delimited list of passwords to
passcheck batchfor bulk analysis.
SecureArmor/
βββ assets/ # Banner images and static assets
βββ passcheck/
β βββ __init__.py # Public API surface
β βββ __main__.py # `python -m passcheck` entry point
β βββ main.py # Backward-compat shim for __main__.py
β βββ models.py # Immutable dataclasses: CriterionResult, PasswordAnalysis
β βββ scoring.py # score_bar(), criteria_summary(), AnalysisSummary
β βββ display.py # Coloured terminal rendering (human-readable)
β βββ utils.py # is_utf_terminal(), masked_password(), leet-table, etc.
β β
β βββ analyzer/ # Core scoring engine (was analyzer.py, 498 lines)
β β βββ __init__.py # re-exports PasswordAnalyzer
β β βββ core.py # PasswordAnalyzer.analyze() β thin orchestrator
β β βββ length.py # minimum / good / excellent length criteria
β β βββ character.py # char-class presence + variety + uniqueness
β β βββ patterns.py # common-password / keyboard-walk / repetition
β β βββ entropy.py # entropy criterion + the entropy estimator
β β βββ strength.py # score -> (label, colour) mapping
β β
β βββ cli/ # Click-based CLI (was cli.py, 565 lines)
β β βββ __init__.py # registers commands + re-exports public API
β β βββ app.py # root Click group + main() entry point
β β βββ exit_codes.py # ExitCode enum
β β βββ errors.py # AnalysisError, PasswordTooLongError
β β βββ security.py # the --password insecure-flag gate
β β βββ analyzer_singleton.py # shared PasswordAnalyzer instance
β β βββ helpers.py # JSON output, NFC/length check, run-analysis
β β βββ check_command.py # `passcheck check`
β β βββ batch_command.py # `passcheck batch`
β β βββ interactive.py # the interactive prompt loop
β β
β βββ constants/ # Tunables + data (was constants.py, 650 lines)
β β βββ __init__.py # re-exports the full original surface
β β βββ weights.py # SCORE_WEIGHTS
β β βββ thresholds.py # length/entropy/composition thresholds, strength bands
β β βββ special_chars.py # what counts as a "special" character
β β βββ keyboard_patterns.py # keyboard-walk pattern data
β β βββ common_passwords_data.py # built-in fallback word list (pure data)
β β βββ common_passwords_loader.py # file loading / caching / validation logic
β β
β βββ data/
β βββ common_passwords.txt # optional SecLists-style wordlist (primary source)
βββ tests/
β βββ test_analyzer.py # Test suite (unittest / pytest compatible)
βββ LICENSE.txt
βββ pyproject.toml # Build metadata, tool configuration
βββ README.mdRequirements: Python β₯ 3.10, click >= 8.0, colorama >= 0.4
# 1. Clone the repository
git clone https://github.com/RakkaEvandra06/SecureArmor.git
cd securearmor
# 2. Install runtime dependencies
pip install click colorama
# 3. Install the package in editable mode (recommended for development)
pip install -e . --no-build-isolationpasscheck --helpIf you don't want to install the package, run it directly:
python3 -m passcheck check
# or
python3 -c "from passcheck.cli import main; main()" checkpasscheck
# or explicitly:
passcheck checkpasscheck check -p "MyP@ssw0rd!"
passcheck check --password "MyP@ssw0rd!"passcheck check -p "MyP@ssw0rd!" --json
echo "hunter2" | passcheck batch --jsonSample JSON output:
{
"password_masked": "G*******2",
"password_length": 9,
"score": 67,
"effective_max_score": 100,
"score_percent": 67,
"strength_label": "Strong",
"strength_color": "green",
"entropy_bits": 38.56,
"passed_count": 8,
"total_criteria": 13,
"suggestions": [
"Aim for 12+ characters for a sizeable length bonus.",
"Consider 20+ characters for maximum length credit.",
"Add a special character (e.g. ! @ # $ % ^ & *).",
"Increase length and character variety to raise entropy."
],
"criteria": [
{
"name": "Minimum Length",
"passed": true,
"skipped": false,
"score": 9,
"max_score": 9,
"detail": "9 chars (minimum 8)",
"suggestion": "",
"skip_reason": null
},
{
"name": "Not a Common Password",
"passed": true,
"skipped": false,
"score": 9,
"max_score": 9,
"detail": "not found in common password list",
"suggestion": "",
"skip_reason": null
}
]
}cat passwords.txt | passcheck batch
cat passwords.txt | passcheck batch --json
echo "hunter2" | passcheck batchpasscheck --help
passcheck check --help
passcheck batch --help# Without pytest
python3 tests/test_analyzer.py
# With pytest (recommended, enables coverage reporting)
pytest tests/ -v# Install dev extras
pip install -e ".[dev]"
# Format
black passcheck/
isort passcheck/
# Lint
flake8 passcheck/
mypy passcheck/python -m build
twine check dist/*
twine upload dist/*Contributions are welcome! Here's how to get started:
- Fork the repository and create your branch from
main. - Install dev dependencies:
pip install -e ".[dev]". - Make your changes add or update tests to cover new behaviour.
- Run the full suite and confirm coverage stays β₯ 80 %:
pytest tests/ -v. - Lint your code:
black . && isort . && flake8 . && mypy passcheck/. - Open a Pull Request with a clear description of what changed and why.
Please keep pull requests focused on a single concern. For larger changes, open an issue first to discuss the approach.
Distributed under the MIT License. See LICENSE.txt for the full text.
SecureArmor is developed for educational and research purposes. While it applies established heuristics to estimate password strength, no tool can guarantee that a password is secure in every context. Always pair strong passwords with multi-factor authentication and a reputable password manager.
