PASSWORD FORGE
A password and passphrase generator for anyone who wants a strong password and an honest idea of how strong it is.
A password generator's success state should mean the randomness behind it was secure. A password made from a weak fallback looks exactly like a good one, so the person using it has no way to tell.
So Password Forge refuses. It uses only the browser's cryptographic random source, and if that is missing or fails, it shows an error saying nothing was generated, rather than quietly falling back to a weaker one. Every other problem, like exclusions that leave no usable characters or a length too short to fit each required type, gets its own plain message.
It has two modes. Random passwords run from 6 to 64 characters, with character sets, an option to leave out look-alike characters, custom exclusions and a 'require each type' switch. Passphrases use 3 to 10 words, with a separator, capitals and digits. Characters are picked without bias and shuffled with the same secure source.
Strength is shown as a range of attack scenarios rather than one crack-time figure, from a rate-limited online guesser up to a large offline cluster, on one scale. It also gives an estimate in bits with five labelled bands, and notes when the attack rates were last updated.
The limit: this is an educational strength model, not an audited one. The passphrase wordlist is small, so a five-word passphrase lands in the tool's own 'fair' band, and the estimate is slightly generous when every character type is required.
Next I would swap in a larger, well-known wordlist, correct the estimate for required types, and test the random picks for uniformity over a large number of draws.