Which hash algorithm should you use?
| Use | Recommended | Avoid |
|---|---|---|
| Storing user passwords | Argon2id, bcrypt | MD5, SHA-1, SHA-256 without a slow KDF |
| Verifying downloads | SHA-256, SHA-512 | MD5, SHA-1 |
| Digital signatures, certificates | SHA-256 or stronger | SHA-1 |
| Quick non-security checksums | CRC32, MD5, BLAKE2b | - |
Why password hashes are different
Fast hashes are great for files and terrible for passwords.
A modern GPU computes billions of SHA-256 hashes per second, so a leaked table of SHA-256 passwords falls quickly. bcrypt and Argon2id are slow on purpose and add a random salt to every password.
For new projects, OWASP recommends Argon2id with at least 19 MiB of memory and 2 iterations - the default above. In PHP that is simply password_hash($pw, PASSWORD_ARGON2ID).
Need the hash of a file?
Use the File Hash Checker to compute SHA-256 or MD5 of a download and compare it with the publisher's checksum. To create strong passwords in the first place, use the Password Generator.
Frequently asked questions
Is it safe to hash a real password here?
Yes. Every hash - including bcrypt and Argon2 - is calculated in your browser with WebAssembly. Nothing you type is sent to ScanWith or anywhere else.
Which hash should I use to store passwords?
Use Argon2id or bcrypt. They are deliberately slow and salted, which makes cracking leaked databases expensive. Never store passwords with MD5, SHA-1 or plain SHA-256 - they are built to be fast, which helps attackers.
Why does bcrypt give a different result every time?
bcrypt and Argon2 add a random salt to each hash, so the same password produces a different string each time. To check a password, use the Verify tab - it reads the salt from the stored hash.
Is MD5 still safe?
Not for security. MD5 and SHA-1 have known collision attacks. They are still fine for non-security checksums, such as detecting accidental file corruption, but use SHA-256 or better to verify downloads.
Can a hash be reversed?
No - hashing is one-way. But weak passwords can be found by guessing: attackers hash billions of common passwords and compare. That is why salted, slow hashes and long random passwords matter.