Laravel Packages

Password Strength Estimator Validation in Laravel

Published
Password Strength Estimator Validation in Laravel image

The Laravel Zxcvbn package is a validation rule that estimates password strength using a PHP port of Dropbox's dropbox/zxcvbn JS package. It considers using user inputs as well to determine a score for password guessability:

// In your validation rules
use Illuminate\Validation\Rules\Password;
use Ziming\LaravelZxcvbn\Rules\ZxcvbnRule;
 
$request->validate([
'name' => ['required']
'email' => ['required', 'email'],
'password' => [
'required',
'confirmed',
'min:8',
new ZxcvbnRule([
request('email'),
request('name'),
]),
],
]);
 
// Examples using zxcvbn-php
$weak = $zxcvbn->passwordStrength('password', $userData); // 0 - extremely guessable
$strong = $zxcvbn->passwordStrength('correct horse battery staple'); // 4 - very unguessable

You can define a ZXCVBN_MIN_SCORE configuration value to determine when validation should fail, based on this scale provided by the underlying zxcvbn-php package. The default is 3 but depending on your needs, you can configure it to match any of the following:

  • 0 means the password is extremely guessable (within 10^3 guesses), dictionary words like 'password' or 'mother' score a 0
  • 1 is still very guessable (guesses < 10^6), an extra character on a dictionary word can score a 1
  • 2 is somewhat guessable (guesses < 10^8), provides some protection from unthrottled online attacks
  • 3 is safely unguessable (guesses < 10^10), offers moderate protection from offline slow-hash scenario
  • 4 is very unguessable (guesses >= 10^10) and provides strong protection from offline slow-hash scenario

💻 You can get started with this package on GitHub: ziming/laravel-zxcvbn.

It's important to remember that Laravel has excellent password rules out of the box, including the ability to ensure a password was not present in a previous data leak. See the validation documentation for more details:

use Illuminate\Validation\Rules\Password;
 
Password::min(8)
->letters()
->mixedCase()
->numbers()
->symbols()
->uncompromised();
Paul Redmond photo

Staff writer at Laravel News. Full stack web developer and author.

Sponsored

serpapi logo
SerpApi

The Web Search API for Your LLM and AI Applications

Visit SerpApi

The latest

View all →
Image Dominant Color and HEIC Support in Laravel 13.24 image

Image Dominant Color and HEIC Support in Laravel 13.24

Read article
Official Laravel Zed Extension: LSP for PHP & Blade image

Official Laravel Zed Extension: LSP for PHP & Blade

Read article
Laravel Head: Manage Meta Tags, Open Graph, and JSON-LD image

Laravel Head: Manage Meta Tags, Open Graph, and JSON-LD

Read article
PhpStorm 2026.2 Released image

PhpStorm 2026.2 Released

Read article
Laravel Doctor: Diagnose Your App With One Artisan Command image

Laravel Doctor: Diagnose Your App With One Artisan Command

Read article
CPX: The Composer Package Executor for PHP image

CPX: The Composer Package Executor for PHP

Read article