Two random ASCII characters have 14 bits of entropy, that is easy to determine. I have heard that zxcvbn is one of the best password entropy estimating algortihms, although that NIST algorithm I showed has similar results. https://tech.dropbox.com/ 2012/ 04/ zxcvbn-realistic-password-strength-estimation/