My initial thoughts are just why not do this client side using javascript? No need for the string to leave the client.
They want the password on the server side purely for statistics or some other reason that has nothing to do with scoring how "secure" the password is.
Or run the length and character checks in Javascript, then hash the password and send the hashed version for dictionary lookup.