About this tool
A kid-friendly checker for school login passwords, with plain-language rules and a passphrase builder.
School Portal Password Policy Tester checks a student login password against the threat that actually applies: a classmate who already knows the student's name, birth year, username and school. It tests eight plain-language rules — at least 8 characters, at least one number or symbol, no personal words, no birth year, not a famous password, no keyboard runs, no long repeats, and short enough to fit the login box — and estimates guessing time using the smallest of a character model, a repeat-collapsed model and a known-word model. It also builds a random four-word passphrase from a published 128-word list, so the strength shown assumes an attacker already has that list.
Open School Portal Password Policy Tester on AltFTool — it loads instantly in your browser.
Paste or type the text you're working with.
Choose how it should be transformed or analyzed.
Copy the finished text into your document or post.
Every rule is explained in one sentence, with the reason it matters at school rather than in a data centre.
Uses the cheapest of three ways to describe the password, so a long run of one letter or a list word cannot inflate the score.
It all runs in the browser, so no password idea leaves the device.
At least 8 characters, which is the minimum NIST SP 800-63B sets for a password a person chooses, and 14 or more if you can. Length helps far more than adding symbols: four ordinary words joined with hyphens is longer, easier to remember, and harder to guess than one word with a number stuck on the end.
Because the person most likely to try your password already knows them. Names and birthdays appear on class lists, sports sheets and social media, so a password built from them is guessable by hand in a few tries — long before any software is involved.
For a school login that locks after a few wrong attempts, yes. Four words drawn at random from a 128-word list give about 28 bits of entropy, and with a two-digit ending roughly 40 bits, which is centuries of guessing at a rate-limited login page. It is not enough if a password file ever leaks, which is why the same phrase should never be reused for email or banking.
Change it straight away and tell a teacher or the school IT helpdesk, even if nothing bad has happened yet — messages sent from a hijacked account are the school's problem to sort out, not the student's to hide. Then check that the same password is not in use anywhere else, and change it there too.