- Introduction
- How is this safe?
- Installation
- Usage in Browser
- Usage in Node.js
- Usage in Command Line
- Development
- Project status
password-leak is a JavaScript module that can be used to determine if a password is compromised by checking with the Have I Been Pwned API.
Your passwords are NEVER transmitted to any other system. This library makes use of the Have I Been Pwned API, which implements a k-Anonymity Model so your password can be checked without ever having to give it to any other party.
npm install @mathiscode/password-leak@latestThis package targets modern Node.js versions and exposes a typed, Promise-based API.
<script type="module" src="https://unpkg.com/@mathiscode/password-leak@latest"></script>
<script type="module">
const isLeaked = await isPasswordLeaked('myPassword')
const strength = await checkPasswordStrength('myPassword')
console.log('Is leaked?', isLeaked)
console.log('Strength', strength)
</script>import { isPasswordLeaked, checkPasswordStrength } from '@mathiscode/password-leak'
const isLeaked = await isPasswordLeaked('myPassword')
const strength = await checkPasswordStrength('myPassword')
console.log('Is leaked?', isLeaked)
console.log('Strength', strength)const { checkPasswordStrength, isPasswordLeakedSync } = require('@mathiscode/password-leak')
isPasswordLeakedSync('myPassword', (error, isLeaked) => {
if (error) throw error
console.log('Is leaked?', isLeaked)
})
const strength = checkPasswordStrength('myPassword')
console.log('Strength', strength)The Promise-based API is the recommended interface for new code.
Install globally:
npm install -g @mathiscode/password-leakYou can also use it without installing via npx:
npx @mathiscode/password-leak myPasswordYou can then use it in two ways:
- Interactive mode:
password-leak- Direct mode:
password-leak myPasswordThe command will:
- Print whether the password has been compromised and its strength
- Exit with status code 0 if the password is safe
- Exit with status code 1 if the password is compromised or an error occurs
# Clone the repository
git clone https://github.com/mathiscode/password-leak.git
cd password-leak
# Install dependencies
pnpm install
# Run type-checking
pnpm exec tsc --noEmit
# Run tests
pnpm exec jest --runInBand
# Build the project
pnpm run build
# Lint the codebase
pnpm exec eslint . --ext .ts
# Start the UI demo
pnpm run ui # demo at https://password-leak.vercel.appThis project now uses a modernized setup with:
- TypeScript strict checking
- ESLint and Prettier validation
- CI automation for linting, tests, and type checks
- a safer, non-global export surface for library usage
The recommended API remains the async functions such as isPasswordLeaked and checkPassword.