Online Safety Games for Kids
These four free games teach online safety by showing the machinery instead of listing rules. You inspect realistic scam messages until the tells jump out at you, you build a password and watch your fort grow as the estimated time to guess climbs, you break a real cipher by hand and find out what a key actually is, and you route a packet across the internet to see that your data travels through other people's machines. Children follow safety advice far more reliably once they know why it is true.
- 4 free games
- Ages 8-16
- No download, no sign-up
What each game teaches
Online safety & phishing
Phish or Legit
Players inspect realistic texts, emails, chats and login pages, flag the red flags and decide if each is a scam, including genuine messages so they learn judgement rather than suspicion of everything. Every clue is explained in one line and the run ends with five golden rules they can use on any message.
Play itOnline safety & security
Password Fort
Build a password and watch your fort grow from a wooden fence to a shielded castle as the estimated time to guess climbs. Teaches why length beats symbols, why common words fall first, and why a few random words make a great passphrase.
Play itCodes & encryption
Cipher Lock
Turn a dial to break a two-thousand-year-old cipher using letter frequency. Teaches what a key is, what frequency analysis is, and why 26 possible keys is nowhere near enough.
Play itHow the internet works
Packet Path
Hop a packet router by router across a network, then lose a cable mid-send. Teaches packets, routing and latency - and why the internet survives things breaking.
Play itWhy showing the mechanism beats listing rules
Internet safety is usually delivered as a list: pick a strong password, do not share it, be careful what you click. All correct, all instantly forgotten, because a rule with no mechanism behind it is just an adult being bossy. The fix is to show the attacker's side.
Phish or Legit starts where most real trouble starts: a message. Texts, emails, in-game chats and login pages arrive on a realistic phone, and the player inspects the sender, previews where a link really goes and flags whatever looks wrong before deciding. Every brand is invented, plenty of the messages are genuine, and each reveal circles the clues with a one-line reason - so what sticks is a habit of checking, not a fear of every notification.
Password Fort does that with a live time-to-guess estimate and a fort that grows with it. A cracker does not think - it works through combinations at billions of guesses a second - so what protects you is having too many combinations to get through. Watching the estimate jump when you add two more letters, and barely move when you add a symbol, teaches the real lesson: length beats cleverness. Then type a word from the wordlist and watch the whole thing collapse to nothing regardless of length, which is the reason 'password123' fails instantly.
Cipher Lock introduces the idea of a key. The rule for a Caesar cipher is public and always has been - shift every letter along the alphabet - and the message is still secret as long as nobody knows how far. That separation between a public method and a private key is the foundation of all modern encryption. It also lets the game land its real point: this cipher has only twenty-six possible keys, so you break it by trying them all in a few seconds, which is exactly why modern keys are astronomically large.
Packet Path covers the bit children are rarely told: their data does not travel down a private pipe. It is split into packets and handed from router to router across machines belonging to other organisations, which is simultaneously why the internet survives damage and why encryption matters on a network you do not control.
None of these games contain scare stories, chat features or advertising for other services, and none of them ask for personal information. They are about understanding, and understanding is what survives past the assembly that taught it.
Common questions
What makes a password strong?
Length, overwhelmingly. Every character you add multiplies the number of combinations an attacker has to try, while adding a symbol only widens the alphabet slightly. Four random words are stronger than a short password full of punctuation and far easier to remember. The one thing that ruins any password, however long, is being a word or phrase that appears in a leaked wordlist.
How do you teach children about internet safety?
Show the mechanism rather than issuing rules. A child who has watched a crack-time estimate collapse when they type a common word understands why length matters in a way no poster achieves, and a child who has broken a cipher by trying every key understands what a key is for. Rules with reasons behind them survive; rules on their own do not.
What is encryption, explained simply?
A public method for scrambling a message, plus a private number called a key that says exactly how it was scrambled. Anyone can know the method and still be unable to read the message without the key. Cipher Lock uses a two-thousand-year-old version with only 26 possible keys, which is why you can break it by hand - modern keys have more possible values than there are atoms in the observable universe.
Are these games safe for children to play?
Yes. They run in the browser, need no download, have no chat or multiplayer features, and no account is required to play. If a child does make an account on Plixoo it asks only for a username and a password - no email, no real name and no date of birth - because the safest data to hold is the data you never collect.
Learning earns Pixels
Every game here counts like the rest of Plixoo. Finishing a run earns Pixels, the first completion of each game is worth a bonus, and you spend them on avatars, frames and themes.