Algorithms compared
| Algorithm | Length | Status |
|---|---|---|
| MD5 | 128-bit (32 hex) | Broken for security — fine for non-security checksums |
| SHA-1 | 160-bit (40 hex) | Deprecated for security (collisions demonstrated) |
| SHA-256 | 256-bit (64 hex) | Secure — the modern default |
| SHA-384 / SHA-512 | 384 / 512-bit | Secure, longer output |
Good uses
- File and download integrity — compare the published SHA-256 checksum with your own.
- Caching and de-duplication — identify identical content quickly.
- API signatures — combined with a secret key as HMAC.
- Gravatar URLs use MD5 or SHA-256 of an email address.
Never store passwords with plain hashes
Fast hashes like MD5 or even SHA-256 can be brute-forced billions of times per second. Store passwords with a slow, salted algorithm — bcrypt, scrypt or Argon2 — as provided by your framework (PHP's password_hash, for example).
Privacy
Hashes are computed in your browser (SHA via the Web Crypto API, MD5 in JavaScript); your text is not uploaded. Need random strings instead? Use the Password Generator. Encoding, not hashing? Try the Base64 Encoder.
Frequently asked questions
Can an MD5 or SHA hash be decrypted?
No. Hashes are one-way. Attackers can only guess inputs and compare results, which is why weak passwords are easy to crack.
Is MD5 still safe?
Not for security. MD5 collisions are easy to create. It is still fine for non-security checksums.
Which hash should I use?
SHA-256 for general integrity checks. For passwords, use bcrypt, scrypt or Argon2 instead of a plain hash.
Why does a tiny change give a totally different hash?
That is the avalanche effect, a key property of cryptographic hash functions.

