Password Generator
Create a long, random password for a new account, device or service. Choose the length and character types, then copy the result directly into your password manager. Your password is generated on your device and is not sent to Wild Creek.
Browser-based security tool
Secure Password Generator
Create a random password that matches the rules of the account or service you are using. Generation happens entirely in your browser.
Your generated password
Save the password in a reputable password manager. The copy remains on your clipboard until it is replaced.
Use a different password for every account
A strong password should be both long and unpredictable. Length makes a password harder to guess, while random generation avoids familiar words, dates and patterns that attackers routinely test. For most online accounts, a randomly generated password of 16 to 20 characters is a practical starting point. Some services impose their own length or character restrictions, so adjust the settings when necessary.
The other important rule is uniqueness. Reusing the same password means that a breach at one service can put unrelated accounts at risk. A password manager can create, store and fill a separate password for every login, leaving you with only the manager’s master password to remember.
Choosing the right settings
Keep lowercase and uppercase letters, numbers and symbols selected when the service accepts them. If you must type the password by hand, excluding similar characters can prevent confusion between characters such as zero and uppercase O. The punctuation exclusion is useful when a particular form, device or configuration file rejects certain symbols.
Longer passwords are generally more useful than complicated but short passwords. If a site permits a long password, increasing the length is usually the simplest way to improve resistance to guessing. The randomness estimate shown by the tool is based on the selected character pool and length. It is a useful comparison, not a guarantee of how any particular service protects credentials.
Handle generated passwords carefully
Copy the password only when you are ready to use or save it. Clipboard contents may be visible to other software on the same device and can remain there until you copy something else. After saving the password in its intended account and password manager, replace the clipboard contents with something non-sensitive.
Frequently Asked Questions
Does the generated password leave my browser?
No. This version uses the Web Crypto feature built into a current browser and generates the password on the visitor’s device. It does not submit the password to WordPress or an external service, and the plugin does not save a copy. Other scripts installed on the same website are outside this plugin’s control, so the site should still be kept updated and reviewed carefully.
How does the generator create random passwords?
The generator obtains random values from the browser’s cryptographic random-number source. It uses rejection sampling when selecting characters, which avoids the small selection bias introduced by a simple remainder calculation. It also adds at least one character from every selected character group before securely shuffling the finished password.
How long should a password be?
For an ordinary online account, 16 to 20 random characters is a sound default when the service allows it. A particularly sensitive account or technical credential may justify a longer password. Follow any maximum length and permitted-character rules shown by the service, and never reduce the length merely to make a random password easier to memorise. Store it in a password manager instead.
What does the randomness estimate mean?
The estimate compares password length with the size of the selected character pool and reports the result in bits. More bits indicate a larger set of possible passwords. It assumes genuinely random generation and should not be read as a promise that an account cannot be compromised, because rate limits, password storage, phishing, malware and account recovery procedures also affect security.
Should I exclude similar or ambiguous characters?
Exclude similar characters when a password must be read aloud or typed on another device. Excluding awkward punctuation can help with older forms, command lines or configuration files that treat certain symbols specially. These exclusions make the available pool a little smaller, so compensate with additional length when practical.
Can I use one generated password for several accounts?
No. Give every account its own password. If one service is breached and credentials are exposed, password reuse gives attackers a direct route into every other account using the same value. A password manager makes unique passwords manageable and can also alert you when a password has been reused.
Is copying a password to the clipboard safe?
It is convenient, but it is not permanent secure storage. Applications with clipboard access may be able to read copied content, and the value may be retained in clipboard history. Paste it promptly into the correct destination or password manager, then copy harmless text to replace it. On a shared device, check whether clipboard history is enabled.
