Passwords are generated locally with crypto.getRandomValues — the same cryptographic random source browsers use for TLS — and never leave your device. Ambiguous characters (0/O, 1/l/I) are excluded from the letter sets.
Table of Contents
Choosing a format
Use 20+ characters with symbols for credentials that live in a password manager or a config file. Use a passphrase for anything a person has to type, such as a server console password. Hex is handy for tokens and database passwords where some tools choke on symbols.
Store server passwords in a password manager or vault, never in shell history or tickets, and prefer SSH keys over passwords for root access.
Password generator at a glance



Official documentation: cPanel & WHM documentation, AlmaLinux wiki, Linux man pages.
Related guides: CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback.
Frequently asked questions
Is it safe to generate passwords on a website?
This page generates them entirely in your browser with no network request. You can verify by disconnecting from the internet and clicking Generate.
How long should a root password be?
At least 20 random characters, or a six-word passphrase — and disable password SSH logins in favour of keys.
Which characters can break config files?
Quotes, backslashes, $ and # can cause trouble in shell and some config formats. Choose letters and digits if you are unsure.