{"_id":"zxcvbn2","_rev":"6-6b584ad588510fb4ee1a9c18dc35424c","name":"zxcvbn2","description":"Realistic password strength estimation. Forked for publishing up-to-date version to npm.","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"zxcvbn2","version":"1.0.0","description":"Realistic password strength estimation. Forked for publishing up-to-date version to npm.","main":"index.js","repository":{"type":"git","url":"https://github.com/B2MSolutions/zxcvbn"},"keywords":["realistic","password","strength","estimation","estimate","meter","validate","validation","fork"],"author":{"name":"B2M"},"contributors":[{"name":"James Bloomer","email":"github2@thebloomers.co.uk"},{"name":"Roy Lines","email":"roy@roylines.co.uk"},{"name":"sjwood","email":"octocat@nym.hush.com"}],"license":"MIT","readme":"```\n_________________________________________________/\\/\\___________________\n_/\\/\\/\\/\\/\\__/\\/\\__/\\/\\____/\\/\\/\\/\\__/\\/\\__/\\/\\__/\\/\\________/\\/\\/\\/\\___\n_____/\\/\\______/\\/\\/\\____/\\/\\________/\\/\\__/\\/\\__/\\/\\/\\/\\____/\\/\\__/\\/\\_\n___/\\/\\________/\\/\\/\\____/\\/\\__________/\\/\\/\\____/\\/\\__/\\/\\__/\\/\\__/\\/\\_\n_/\\/\\/\\/\\/\\__/\\/\\__/\\/\\____/\\/\\/\\/\\______/\\______/\\/\\/\\/\\____/\\/\\__/\\/\\_\n________________________________________________________________________\n```\n\n`zxcvbn`, named after a crappy password, is a JavaScript password strength\nestimation library. Use it to implement a custom strength bar on a\nsignup form near you!\n\n`zxcvbn` attempts to give sound password advice through pattern matching\nand conservative entropy calculations. It finds 10k common passwords,\ncommon American names and surnames, common English words, and common\npatterns like dates, repeats (aaa), sequences (abcd), and QWERTY\npatterns.\n\nFor full motivation, see:\n\nhttp://tech.dropbox.com/?p=165\n\n# Installation\n\n``` html\n<script type=\"text/javascript\" src=\"zxcvbn-async.js\">\n</script>\n```\n\nis the best way to add `zxcvbn` to your site. Host `zxcvbn.js` and\n`zxcvbn-async.js` somewhere on your web server, and make the hardcoded\npath inside `zxcvbn-async.js` point to `zxcvbn.js`. A relative path works\nwell.\n\n`zxcvbn-async.js` is a tiny 350 bytes. On `window.load`, after your page\nloads and renders, it'll fetch `zxcvbn.js`, which is more like 700k (330k\ngzipped), most of which is a series of dictionaries.\n\nI haven't found 700k to be too large -- especially because a password\nisn't the first thing a user typically enters on a registration form.\n\n`zxcvbn.js` can also be included directly:\n\n``` html\n<script type=\"text/javascript\" src=\"zxcvbn.js\">\n</script>\n```\n\nBut this isn't recommended, as the 700k download will block your\ninitial page load.\n\n`zxcvbn` adds a single function to the global namespace:\n\n``` javascript\nzxcvbn(password, user_inputs)\n```\n\nIt takes one required argument, a password, and returns a result object.\nThe result includes a few properties:\n\n``` coffeescript\nresult.entropy            # bits\n\nresult.crack_time         # estimation of actual crack time, in seconds.\n\nresult.crack_time_display # same crack time, as a friendlier string:\n                          # \"instant\", \"6 minutes\", \"centuries\", etc.\n\nresult.score              # [0,1,2,3,4] if crack time is less than\n                          # [10**2, 10**4, 10**6, 10**8, Infinity].\n                          # (useful for implementing a strength bar.)\n\nresult.match_sequence     # the list of patterns that zxcvbn based the\n                          # entropy calculation on.\n\nresult.calculation_time   # how long it took to calculate an answer,\n                          # in milliseconds. usually only a few ms.\n````\n\nThe optional `user_inputs` argument is an array of strings that `zxcvbn`\nwill add to its internal dictionary. This can be whatever list of\nstrings you like, but is meant for user inputs from other fields of the\nform, like name and email. That way a password that includes the user's\npersonal info can be heavily penalized. This list is also good for\nsite-specific vocabulary.\n\nWhen `zxcvbn` loads (after the async script fetch is complete), it'll\ncheck if a function named `zxcvbn_load_hook` is defined, and run it with\nno arguments if so. Most sites shouldn't need this.\n\n# Development\n\nBug reports and pull requests welcome!\n\n`zxcvbn` is written in CoffeeScript and Python. `zxcvbn.js` is built with\n`compile_and_minify.sh`, which compiles CoffeeScript into JavaScript,\nthen JavaScript into efficient, minified JavaScript.\n\nFor development, include these scripts instead of `zxcvbn.js`:\n\n``` html\n<script type=\"text/javascript\" src=\"adjacency_graphs.js\">\n</script>\n<script type=\"text/javascript\" src=\"frequency_lists.js\">\n</script>\n<script type=\"text/javascript\" src=\"matching.js\">\n</script>\n<script type=\"text/javascript\" src=\"scoring.js\">\n</script>\n<script type=\"text/javascript\" src=\"init.js\">\n</script>\n```\n\nData lives in the first two scripts. These get produced by:\n\n```\nscripts/build_keyboard_adjacency_graph.py\nscripts/build_frequency_lists.py\n```\n\n`matching.coffee`, `scoring.coffee`, and `init.coffee` make up the rest of the\nlibrary.\n\n`init.js` needs to come last, otherwise script order doesn't matter.\n\nI recommend setting up coffee-mode in emacs, or whatever equivalent, so\nthat CoffeeScript compiles to js on save. Otherwise you'll need to\nrepetitively run `compile_and_minify.js`\n\n\n# Acknowledgments\n\nDropbox, thank you in so many ways, but in particular, for supporting\nindependent projects both inside and outside of hackweek.\n\nMany thanks to Mark Burnett for releasing his 10k top passwords list:\n\nhttp://xato.net/passwords/more-top-worst-passwords\n\nand for his 2006 book,\n\"Perfect Passwords: Selection, Protection, Authentication\"\n\nHuge thanks to Wiktionary contributors for building a frequency list\nof English as used in television and movies:\nhttp://en.wiktionary.org/wiki/Wiktionary:Frequency_lists\n\nLast but not least, big thanks to xkcd :)\nhttps://xkcd.com/936/\n","readmeFilename":"README.md","_id":"zxcvbn2@1.0.0","dist":{"shasum":"ea5c699725d16d5f4f63c64f8e96987a66c837e9","tarball":"https://registry.npmjs.org/zxcvbn2/-/zxcvbn2-1.0.0.tgz","integrity":"sha512-a4bSsLBii08lbLHp0Lq0CPcyyqasUCGGPCbLCM3FeDuLyvbHkOhDNtJd6NspMTVSQQBW64gVGoRg9GGfkdCmLg==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDhONK+HaU34ZxbC8Dk4WyWb9fBYmNpWodYi9UalXdBYgIgIaDxDIuFQVU0X1VtBCkqNtmXRYM1j0hl1XArcDtpMT8="}]},"_from":".","_npmVersion":"1.2.11","_npmUser":{"name":"b2mdevelopment","email":"development@b2m-solutions.com"},"maintainers":[{"name":"b2mdevelopment","email":"development@b2m-solutions.com"}]}},"readme":"```\n_________________________________________________/\\/\\___________________\n_/\\/\\/\\/\\/\\__/\\/\\__/\\/\\____/\\/\\/\\/\\__/\\/\\__/\\/\\__/\\/\\________/\\/\\/\\/\\___\n_____/\\/\\______/\\/\\/\\____/\\/\\________/\\/\\__/\\/\\__/\\/\\/\\/\\____/\\/\\__/\\/\\_\n___/\\/\\________/\\/\\/\\____/\\/\\__________/\\/\\/\\____/\\/\\__/\\/\\__/\\/\\__/\\/\\_\n_/\\/\\/\\/\\/\\__/\\/\\__/\\/\\____/\\/\\/\\/\\______/\\______/\\/\\/\\/\\____/\\/\\__/\\/\\_\n________________________________________________________________________\n```\n\n`zxcvbn`, named after a crappy password, is a JavaScript password strength\nestimation library. Use it to implement a custom strength bar on a\nsignup form near you!\n\n`zxcvbn` attempts to give sound password advice through pattern matching\nand conservative entropy calculations. It finds 10k common passwords,\ncommon American names and surnames, common English words, and common\npatterns like dates, repeats (aaa), sequences (abcd), and QWERTY\npatterns.\n\nFor full motivation, see:\n\nhttp://tech.dropbox.com/?p=165\n\n# Installation\n\n``` html\n<script type=\"text/javascript\" src=\"zxcvbn-async.js\">\n</script>\n```\n\nis the best way to add `zxcvbn` to your site. Host `zxcvbn.js` and\n`zxcvbn-async.js` somewhere on your web server, and make the hardcoded\npath inside `zxcvbn-async.js` point to `zxcvbn.js`. A relative path works\nwell.\n\n`zxcvbn-async.js` is a tiny 350 bytes. On `window.load`, after your page\nloads and renders, it'll fetch `zxcvbn.js`, which is more like 700k (330k\ngzipped), most of which is a series of dictionaries.\n\nI haven't found 700k to be too large -- especially because a password\nisn't the first thing a user typically enters on a registration form.\n\n`zxcvbn.js` can also be included directly:\n\n``` html\n<script type=\"text/javascript\" src=\"zxcvbn.js\">\n</script>\n```\n\nBut this isn't recommended, as the 700k download will block your\ninitial page load.\n\n`zxcvbn` adds a single function to the global namespace:\n\n``` javascript\nzxcvbn(password, user_inputs)\n```\n\nIt takes one required argument, a password, and returns a result object.\nThe result includes a few properties:\n\n``` coffeescript\nresult.entropy            # bits\n\nresult.crack_time         # estimation of actual crack time, in seconds.\n\nresult.crack_time_display # same crack time, as a friendlier string:\n                          # \"instant\", \"6 minutes\", \"centuries\", etc.\n\nresult.score              # [0,1,2,3,4] if crack time is less than\n                          # [10**2, 10**4, 10**6, 10**8, Infinity].\n                          # (useful for implementing a strength bar.)\n\nresult.match_sequence     # the list of patterns that zxcvbn based the\n                          # entropy calculation on.\n\nresult.calculation_time   # how long it took to calculate an answer,\n                          # in milliseconds. usually only a few ms.\n````\n\nThe optional `user_inputs` argument is an array of strings that `zxcvbn`\nwill add to its internal dictionary. This can be whatever list of\nstrings you like, but is meant for user inputs from other fields of the\nform, like name and email. That way a password that includes the user's\npersonal info can be heavily penalized. This list is also good for\nsite-specific vocabulary.\n\nWhen `zxcvbn` loads (after the async script fetch is complete), it'll\ncheck if a function named `zxcvbn_load_hook` is defined, and run it with\nno arguments if so. Most sites shouldn't need this.\n\n# Development\n\nBug reports and pull requests welcome!\n\n`zxcvbn` is written in CoffeeScript and Python. `zxcvbn.js` is built with\n`compile_and_minify.sh`, which compiles CoffeeScript into JavaScript,\nthen JavaScript into efficient, minified JavaScript.\n\nFor development, include these scripts instead of `zxcvbn.js`:\n\n``` html\n<script type=\"text/javascript\" src=\"adjacency_graphs.js\">\n</script>\n<script type=\"text/javascript\" src=\"frequency_lists.js\">\n</script>\n<script type=\"text/javascript\" src=\"matching.js\">\n</script>\n<script type=\"text/javascript\" src=\"scoring.js\">\n</script>\n<script type=\"text/javascript\" src=\"init.js\">\n</script>\n```\n\nData lives in the first two scripts. These get produced by:\n\n```\nscripts/build_keyboard_adjacency_graph.py\nscripts/build_frequency_lists.py\n```\n\n`matching.coffee`, `scoring.coffee`, and `init.coffee` make up the rest of the\nlibrary.\n\n`init.js` needs to come last, otherwise script order doesn't matter.\n\nI recommend setting up coffee-mode in emacs, or whatever equivalent, so\nthat CoffeeScript compiles to js on save. Otherwise you'll need to\nrepetitively run `compile_and_minify.js`\n\n\n# Acknowledgments\n\nDropbox, thank you in so many ways, but in particular, for supporting\nindependent projects both inside and outside of hackweek.\n\nMany thanks to Mark Burnett for releasing his 10k top passwords list:\n\nhttp://xato.net/passwords/more-top-worst-passwords\n\nand for his 2006 book,\n\"Perfect Passwords: Selection, Protection, Authentication\"\n\nHuge thanks to Wiktionary contributors for building a frequency list\nof English as used in television and movies:\nhttp://en.wiktionary.org/wiki/Wiktionary:Frequency_lists\n\nLast but not least, big thanks to xkcd :)\nhttps://xkcd.com/936/\n","maintainers":[{"name":"b2mdevelopment","email":"development@b2m-solutions.com"}],"time":{"modified":"2022-06-29T18:11:20.389Z","created":"2013-08-28T15:32:38.380Z","1.0.0":"2013-08-28T15:32:40.443Z"},"author":{"name":"B2M"},"repository":{"type":"git","url":"https://github.com/B2MSolutions/zxcvbn"},"users":{"tobitobitobi":true}}