About this tool
Weighted 21-point TP-Link hardening audit covering the admin account, WPA encryption, WPS, remote management and firmware, with a WPA2 crack-time check.
This TP-Link hardening checklist walks a 21-point security pass over an Archer or Deco router — admin account, WPA2/WPA3 encryption, WPS, remote WAN management, UPnP, port forwards and firmware — and scores what is still open, weighted by how much exposure each step actually removes. It gives the exact menu path under tplinkwifi.net for every step, so you are not hunting through Advanced > System Tools. A built-in WPA2 crack-time estimator applies the PBKDF2-HMAC-SHA1 4096-iteration handshake maths to show how long your current Wi-Fi passphrase would survive an offline attack.
Open TP-Link Router Hardening Checklist on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Each step carries points based on real exposure removed, and a missing critical step caps the score at 60%.
Every item names the page it lives on, from Wireless Settings to System Tools > Administration.
The passphrase estimator uses published hashcat mode 22000 speeds rather than a vague strength meter.
Most Archer routers answer at tplinkwifi.net or 192.168.0.1, and older units shipped with admin as both username and password. Newer firmware forces you to create a password during first setup, and the label on the base of the unit is the authoritative source for your specific model.
Yes. The eight-digit WPS PIN is checked in two halves, which reduces a brute-force search from 100 million combinations to about 11,000, and vulnerable chipsets fall to the offline Pixie Dust attack in seconds. Disable both the PIN and the push button under Advanced > Wireless > WPS.
It publishes the admin login on the public internet, where scanners find it within hours. The Archer AX21 command-injection flaw tracked as CVE-2023-1389 was mass-exploited by Mirai variants through exactly that surface in 2023, so leave Remote Management disabled and use a VPN back to the house if you genuinely need remote access.
Twelve or more characters mixing cases, digits and a symbol puts a brute-force attack far beyond practical reach, while eight lowercase letters falls in about 15 hours on a single high-end GPU. Avoid anything on a public wordlist, since dictionary attacks find those in the first few thousand guesses regardless of length.