it's mostly good. NIST abolished their algo for pasword entropy estimation some time ago. i do not much like any password strength tests, most of which rate any number of terrible passwords as strong. as such i think they give a false sense of security. maybe consider cracklib. as DenisM said, always use SSL for all traffic if security matters and don't trust SO for security advice.
The only really useful password strength test would be one that said "A stock Thinkpad would be able to brute force this password in $x hours and $y minutes." Might make people think twice about that six character password.
;-)