The checker estimates entropy as length x log2(size of the character pool you used): lowercase, uppercase, digits and symbols each widen the pool. It then subtracts for common passwords, repeated characters, keyboard runs and simple sequences like 1234 or abcd. The crack time assumes an attacker who can test 10 billion guesses per second against a fast, unsalted hash, which is a pessimistic but realistic offline scenario. This is a rough estimate, not a guarantee.
The check runs in JavaScript inside your browser and nothing is uploaded or stored. Still, as a habit, test a similar password rather than one you use for your bank.
Length matters most. A random passphrase of four or five unrelated words, or a 14+ character random password from a password manager, beats short passwords with clever substitutions. Use a different password for every account.
See also: Password Generator ยท Random Number Generator