Security Health in the Extension

A scored view of your personal credentials — how reusable, how fresh, and whether any have
turned up in a public breach.

ℹ️

Personal items only. Corporate and team items are deliberately out of scope: your
personal security score should not move because a colleague reused a password in a shared
folder. The web console has its own, differently scoped Security Health page.

How the scan runs

Opening Security Health starts a scan. It cannot score what it has not read, so it fetches
each personal item's value, up to ten at a time.

A scan in progress
Progress is shown item by item, with the gauge still settling

StageWhat you see
ListingThe gauge is indeterminate
FetchingScanning passwords… 65/66 and a progress bar
SettlingRefining scores… under the gauge
DoneA green bar and All personal items were scanned

The gauge starts red and blends toward its true color as the scan completes, so an early
glance never reads as a real score. A single slow item cannot block the whole screen — each
fetch times out independently.

Results are cached for the session. Use the refresh icon to rescan, and the info icon
for an in-product explanation.

How the score is calculated

The protection score runs 0–100, from two pillars worth 50 points each.

Uniqueness (50 points)

Reduced by two independent problems, applied together:

FactorEffect
ReuseThe proportion of your password items sharing a password with at least one other item
BreachThe proportion matching the bundled leaked-password list

Both are ratios of your total password count, so ten reused passwords out of ten costs far
more than ten out of a thousand.

Freshness (50 points)

The proportion of items — passwords and passkeys — updated within the last 90 days. An
item with no recorded date counts as stale.

Worked example

With 10 passwords, 3 of them reused and 1 breached, and 5 items fresh within 90 days:

PillarWorkingPoints
Uniqueness50 × (1 − 0.30) × (1 − 0.10)31.5
Freshness50 × (5 ÷ 10)25.0
Total57

Special cases

CaseScore
Empty vault100
Lists not yet loadedIndeterminate — no number shown

Bands

ScoreColor
0–35Red
36–66Orange
67–100Green

Protection score, gauge view
Gauge view

Switch to Graph to see each metric as a node, sized and colored by its contribution.

Protection score, graph view
Graph view — drag, zoom and pan; select a node to expand it

The five metrics

TileCountsAffects score
Same passwordItems sharing a password with at least one otherYes
Stale 90d+Not edited in 90+ days, or with an unknown dateYes
Leaked passwordsFound in public breach dataYes
PasskeysPasskeys in your personal folderNo
OTPItems carrying an otpauth URI or an OTP fieldNo

Passkeys and OTP are reported because they are good signals to act on, but they do not move
the number — adding a passkey should not compensate for a reused password.

Select any tile to open the list of items behind it.

The breach check runs offline

ℹ️

Passwords are compared against a filter bundled inside the extension. No password, and
no hash of one, is sent anywhere — not to Akeyless, not to any third-party breach service.

The check is one-directional: a flagged password is definitely in the leaked set; an unflagged
one is probably not.

Acting on the results

FindingDo this
LeakedChange it at the source, then update the item — highest priority
Same passwordGenerate a unique one per item with the password generator
Stale 90d+Rotate the ones that matter; a long-lived password on a dormant account matters less
No OTPAdd an authenticator where the site supports it — see Adding and Using One-Time Passwords

If it shows nothing

Security Health covers personal items only, and is hidden entirely when the Personal area is.
See Account Policies Affecting the Extension.

Related


Did this page help you?
Footer Section