Security Health

A scored view of your personal credentials — how reusable, how fresh, and whether any have
turned up in a public breach.

Security Health
A 35% protection score, with the Same password metric selected and its items listed below

ℹ️

Personal vault only. Passwords are checked locally against an offline leak list —
nothing leaves this browser. Corporate and team items are deliberately out of scope:
your personal security score should not move because a colleague reused a password in a
shared folder.

The scan

Opening Security Health starts a scan. It cannot score what it has not read, so it fetches
each personal item's value.

Progress is shown beneath the gauge — Scanned 232 of 232 passwords — and Refresh in the
top right rescans. The ⓘ icon explains the score in product.

Results are cached for the session.

How the score is calculated

The protection score runs 0–100, from two pillars worth 50 points each.

Uniqueness (50 points)

Reduced by two independent problems, applied together:

FactorEffect
ReuseThe proportion of password items sharing a password with at least one other
BreachThe proportion matching the bundled offline leak list

Both are ratios of your total password count, so three reused out of five costs far more than
three out of three hundred.

Freshness (50 points)

The proportion of items — passwords and passkeys — updated within the last 90 days. An
item with no recorded date counts as stale.

Worked example

With 10 passwords, 3 reused and 1 breached, and 5 items fresh within 90 days:

PillarWorkingPoints
Uniqueness50 × (1 − 0.30) × (1 − 0.10)31.5
Freshness50 × (5 ÷ 10)25.0
Total57

Special cases

CaseScore
Empty vault100
Lists not yet loadedIndeterminate

The five metrics

TileCountsAffects score
Same passwordItems that share an identical passwordYes
Stale 90d+Not updated in the last 90 daysYes
Leaked passwordsMatch against the offline top-leaked listYes
PasskeysPersonal passkeys in your vaultNo
OTPPasswords with a saved authenticator codeNo

Passkeys and OTP are reported because they are useful signals, but they do not move the
number — adding a passkey should not compensate for a reused password.

The item table

Select a tile and the table below fills with the items behind it. The selected tile is
outlined.

ColumnShows
NameItem name with its folder path
TypePassword, Passkey, and so on
Created Date, Updated DateTimestamps — the Updated date is what drives the staleness metric

The table paginates with its own Rows per page control, so a metric with hundreds of items
stays usable.

Acting on the results

FindingDo this
LeakedChange it at the source, then update the item — highest priority
Same passwordGenerate a unique one per item
Stale 90d+Rotate the ones that matter; a dormant account matters less
No OTPAdd an authenticator where the site supports it

Related


Did this page help you?
Footer Section