Password strength is such an irrelevant concept, when it has become virtually impossible to crack any account for a decent application from the outside. Decent application meaning you can't just brute force at login.
However, you will get in trouble if the database is compromised and your password is "abc", that's true. I use the same minimal password for everything I don't care about, then one real password for each thing I do care about (and another general one for those fuckers than want 8 characters a symbol a number and an uppercase). And yes password reuse and social engineering are much bigger problems than password strenght.
This site is dumb anyways. You can enter an english sentence and it will say "54 decillion years", but that kind of password can be found in seconds with a dictionary attack