About this tool
Weighted 16-point audit of smart lock accounts, guest codes, door hardware and offline fallback, with a keypad-code guessing-time estimate.
This checklist audits a smart lock across sixteen weighted controls — app account protection, keypad and guest codes, door hardware and the offline fallback — and estimates how long a keypad code survives guessing using a 10^n search with your lock's actual lockout rule. Controls that let someone else open the door, or leave you locked out, carry the most weight, and any missing critical control caps the score. It is written for anyone fitting a retrofit or replacement lock at a front door, a rental or a holiday let.
Open Smart Lock Security Checklist on AltFTool — it loads instantly in your browser.
Provide your input — an image, text, or data.
Let the tool analyze or generate the result.
Review, refine, and reuse the output wherever you need it.
Two-factor on the app account and a changed factory code outrank convenience settings.
Digits, seconds per attempt and the lockout rule combine into an average time to guess.
Strike plate screws and letterbox fishing sit alongside passwords, because that is how doors actually fail.
For a lock with no lockout, no: 10,000 combinations at two seconds a try averages about 2.8 hours of standing at the keypad. With a typical five-tries-then-60-seconds lockout the same code averages around 19 hours, and moving to six digits pushes it past a decade — so six digits plus a lockout is the practical minimum.
Bluetooth and Z-Wave locks keep working locally because the keypad and the radio pairing do not depend on the internet, and the batteries are in the lock. Cloud-dependent models may refuse remote unlocking during an outage, so test yours with the router switched off and keep a mechanical key or override route stored off-site.
Create a named user with their own code and, where the lock supports it, a schedule or single-use limit — for example valid 09:00 to 12:00 on one date. That keeps the access log meaningful, lets you revoke one person without changing everyone else's code, and stops the code being passed on afterwards.
It is hooking a wire through the letterbox to turn the thumb-turn from outside, and retrofit smart locks are especially exposed because they mount on that thumb-turn. A letterbox cowl, a restrictor, or a lock with a shielded thumb-turn removes the attack; no app setting can.