Free · Private · In-Browser

MD5 Checksum Explainer

See why MD5 is legacy and which browser-supported hashes to use instead.

Output
 

Why MD5 is legacy

MD5 still shows up in tutorials, but it is broken for security and no longer safe for verifying authenticity. This explainer lays out why MD5 is legacy and which modern, browser-supported hashes (like SHA-256) you should use instead.

Understanding the difference between a fast error-detection checksum and a secure hash prevents real mistakes, like trusting MD5 to verify a download. Read the rationale and use the recommended alternatives for anything that matters.

Why not MD5

MD5 is fine for a non-security checksum but broken for authenticity, since collisions can be manufactured — use SHA-256 there. The explainer runs in your browser.

Frequently asked questions

Why can't the browser calculate MD5 here?

The browser's Web Crypto API leaves out MD5 because it is broken for security uses. The tool shows a SHA-256 hash instead.

Is MD5 still useful?

For spotting accidental file corruption or matching a legacy checksum, yes. For passwords, signatures, or anything security-related, no.

What should I use instead?

SHA-256 for checksums and signatures, and bcrypt, scrypt, or Argon2 for passwords.

Take it further
Developer Tools

Practical utilities for everyday web development work.

Learn more