Emergency server help: get in touch

Secure Password Generator

Generate strong random passwords or passphrases in your browser using the Web Crypto API — for root, database, WHM, panel and API credentials.

Status
Live
Last updated
October 3, 2026

Passwords are generated locally with crypto.getRandomValues — the same cryptographic random source browsers use for TLS — and never leave your device. Ambiguous characters (0/O, 1/l/I) are excluded from the letter sets.

Choosing a format

Use 20+ characters with symbols for credentials that live in a password manager or a config file. Use a passphrase for anything a person has to type, such as a server console password. Hex is handy for tokens and database passwords where some tools choke on symbols.

Store server passwords in a password manager or vault, never in shell history or tickets, and prefer SSH keys over passwords for root access.

Password generator at a glance

Secure Password Generator summary card: Passwords are generated locally with crypto.getRandomValues — the same cryptographic random source browsers use for TLS…
In short: Passwords are generated locally with crypto.getRandomValues — the same cryptographic random source browsers use for TLS — and never leave your device.
Password generator – overview of the steps
Password generator: the sections of this tool at a glance.
Secure Password Generator questions answered: Is it safe to generate passwords on a website? How long should a root password be?
Answers: Is it safe to generate passwords on a website? How long should a root password be?

Official documentation: cPanel & WHM documentation, AlmaLinux wiki, Linux man pages.

Related guides: CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback.

Frequently asked questions

Is it safe to generate passwords on a website?

This page generates them entirely in your browser with no network request. You can verify by disconnecting from the internet and clicking Generate.

How long should a root password be?

At least 20 random characters, or a six-word passphrase — and disable password SSH logins in favour of keys.

Which characters can break config files?

Quotes, backslashes, $ and # can cause trouble in shell and some config formats. Choose letters and digits if you are unsure.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.