CipherLayer
Home / Tools / Caesar Cipher

Caesar Cipher + Frequency Cracker

Encrypt with a 0–25 shift, decrypt if you know the key, or paste ciphertext and let chi-squared frequency analysis pick the key for you. This is an educational tool — it shows why a shift cipher is not security.

Classical Educational Chi² attack Auto-crack Pure JS
Broken since the 800s. Al-Kindi described the frequency-analysis attack in A Manuscript on Deciphering Cryptographic Messages. A modern computer recovers the shift in milliseconds. Do not use Caesar to protect anything real.

Inputs

3

Shift of 3 is the historical Caesar cipher. Shift of 0 returns plaintext.

Output

// Output will appear here
Status
—
Shift used
—
Length
—

Letter Frequency Histogram

Compare observed letter counts in the current input against the expected English distribution. If the input is Caesar-shifted English, the bars should look like English, just rotated.

Observed (current input)

Expected (English)

Why this tool, and why this version

The Caesar cipher shifts every letter by a fixed amount. Julius Caesar reportedly used shift 3 to send military orders. For 2,000 years people assumed it provided some kind of secrecy. It does not.

In the 9th century, the Arab polymath Al-Kindi wrote the earliest known description of frequency analysis. The insight is devastating in its simplicity: in any long message, every letter of the alphabet appears at roughly its natural frequency. Shift the alphabet and the histogram shifts with it. Read the histogram, identify the most common letter, and the most common letter in English is e. Subtract that distance from the shift, and you've recovered the key.

This tool runs that attack live. Paste any Caesar ciphertext of ~80 characters or more, click Crack, and you get the shift, the chi-squared score, and the decrypted plaintext for every candidate. The lowest chi-squared value wins.

The chi-squared statistic is borrowed from physics. It measures how far an observed distribution deviates from an expected one. For letters, the expected distribution is the frequency of A–Z in English prose. The observed distribution is what your ciphertext actually contains. A small chi-squared value means "looks like English"; a large value means "doesn't".

Who this is for

Students of classical cryptography

You need to see the attack, not just the cipher. This tool runs the attack. Read the chi-squared scores, see how even short ciphertexts betray the shift, and understand why "shift the alphabet" was never going to work as security.

History enthusiasts

Al-Kindi's manuscript predates European cryptography by 600 years. The frequency-analysis attack wasn't rediscovered until the Renaissance. This tool makes the math behind that historical pivot concrete and reproducible.

Puzzle solvers and the curious

Got a Caesar ciphertext from a puzzle book, geocache, or escape room? Paste it here and the cracker will produce the plaintext. You'll also see why the puzzle was never actually hard — for a computer.

Frequently asked questions

How does the automatic cracker know which shift is correct? ▶
It tries all 26 shifts, decrypts the ciphertext with each one, then measures how English-like the result looks using chi-squared scoring against the expected English letter distribution. The shift with the lowest chi² is the most likely answer. This works because English has a highly distinctive letter frequency profile — a real shift cipher cannot hide that profile, only rotate it.
What's a "good" chi-squared value? ▶
For English text of around 1,000 characters, chi² typically falls between 50 and 400. A value below ~250 strongly suggests English. A value above ~1,000 strongly suggests non-English text or a very short sample. With only 30 characters of ciphertext, the noise dominates and multiple shifts may score similarly. The cracker sorts all 26 candidates by chi² so you can inspect the top contenders manually.
Why do you ignore non-A–Z characters? ▶
The classical Caesar cipher was defined over the Latin alphabet. Digits, punctuation, and spaces are preserved unchanged. Our implementation follows that convention. For the chi-squared attack, we ignore everything except A–Z — including spaces — because frequency analysis on punctuation doesn't help distinguish English from random.
When was the Caesar cipher actually broken? ▶
The first documented attack is Al-Kindi's 9th-century treatise. The technique was known to Arab cryptanalysts well before Europeans caught on. The cipher itself is sometimes called the "shift cipher" because "Caesar cipher" implies shift 3 — but any fixed shift can be broken with exactly the same method, in any century.
Is this the ROT13 I've seen online? ▶
Yes. ROT13 is Caesar with shift 13. It is its own inverse — applying ROT13 twice returns the original text. Online forums use ROT13 to obscure spoilers and puzzle answers. It is not encryption. Use the shift input set to 13 and you get ROT13.
Can I use this for something secret? ▶
No. There are 25 non-trivial Caesar shifts. Brute-forcing them takes microseconds. Even if your enemy lacks a computer, they can try all 25 by hand in an afternoon. For actual confidentiality use AES-GCM, ChaCha20-Poly1305, or any modern authenticated cipher. See the rest of CipherLayer.

Limitations you should know