Password Health Audit (Check an Exported Password File)
Find breached, reused and weak passwords in your export — on your device.
Try before you buy.
- Free preview: every count, with the first half of the fix list and of the reused-password groups (up to 10 rows each).
- Locked until you unlock it: download and print.
- Unlock: Pro pass, ₹179 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Your password export
The file is read on this device only: it is never uploaded or stored, and no password is ever shown. For the breach check, only the first 5 characters of each password’s SHA-1 hash are sent to Have I Been Pwned.
How to export your passwords
- Chrome: menu (⋮) → Passwords and autofill → Google Password Manager → Settings → Export passwords → Download file.
- Firefox: open the Passwords page (about:logins), open its menu (⋯) and choose Export Passwords….
- Apple Passwords (Mac): File → Export All Passwords to File → Export Passwords.
- Bitwarden (web app): Tools → Export → File format .csv → Export.
- 1Password 8: File → Export (Mac), or ⋯ → Export (Windows, Linux) → CSV → Export Data.
- Other browsers and password managers: look for Export in their password settings. Any CSV file with a password column works.
Every one of these files holds your passwords in readable text. Keep it on this device, and delete it when you are done.
Your password health
Fix list
“Change password” opens the site’s own change-password address in a new tab. Sites that do not support that address show another page or an error: then sign in and open the site’s security settings.
Passwords used for more than one account
The report
The printed report and the CSV list sites, user names, problems and what to do — never a password.
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
About the Password Health Audit (Check an Exported Password File)
Open the password file you exported from Chrome, Firefox, Apple Passwords, Bitwarden, 1Password or another password manager, and see — without uploading it — which passwords are in data breaches, which are reused across accounts, which are weak or variations of each other, which sites are saved with a plain http address and, when the export records dates, which passwords are old. The result is a fix list in the order to work through it, starting with e-mail accounts, and a report for your family or office that never shows a password.
The file is read into this tab’s memory and nothing else: it is never stored, and no password is ever displayed. Strength is estimated with zxcvbn on your device; the breach check uses Have I Been Pwned’s k-anonymity range API, which receives only the first 5 characters of each password’s SHA-1 hash.
Without a pass the result is a free preview: every count, with the first half of the fix list and of the reused-password groups (up to 10 rows each); the printed report and the CSV unlock with a Pro pass.
How to use it
- Get the CSV file from your browser or password manager — the page lists where Chrome, Firefox, Apple Passwords, Bitwarden and 1Password keep it.
- Choose the file or drop it on the page. Its columns are recognised by their headings; if none is called “password”, pick the columns yourself.
- Leave Check each password against known data breaches on (only hash prefixes are sent), choose when a password counts as old, and press Audit the passwords.
- Work through the fix list from the top: Fix now first — passwords in breaches, and reused e-mail passwords — then reused and very weak ones, then the rest. Change password opens the site’s own change-password page in a new tab, where the site supports it.
- Give the report a title and, if you will share the unlocked report, hide the user names. The printed report and the CSV unlock with a Pro pass; without one the page shows the free preview.
- Delete the CSV file from your browser or password manager when you are done, and empty the Bin: it still holds every password in readable text.
Examples
name,url,username,password,note accounts.google.com,https://accounts.google.com/,ann@gmail.com,Tulip-Harbor-Quartz-41, shop.example,https://shop.example/login,ann,Tulip-Harbor-Quartz-41,
Fix now: accounts.google.com (an e-mail account; reused, group A) · Fix soon: shop.example (reused, group A)
The password is strong and in no breach list, but a leak at the shop would also open the mailbox, and from there every other account. The result lists the accounts that share it as group A and never shows the password itself.
"url","username","password",…,"timePasswordChanged" "https://forum.example","ann","k2$Fh8!qLm#4Zr",…,"1546300800000"
Check: forum.example — old (not changed for more than 5 years)
Firefox records when each password last changed (in milliseconds); old passwords are worth changing if the site has had a breach since.
bank.example,https://bank.example/,ann,qwerty123,
Fix now: bank.example — in data breaches (seen more than 13 million times), very weak
Have I Been Pwned’s counts grow as breaches are added, so the number you see may differ.
Common uses
- A family check-up: find the passwords everyone reuses and fix the e-mail accounts first.
- A small office without an IT department, before or after a phishing scare.
- Cleaning up an old browser’s saved passwords before moving to a password manager.
- Checking a whole list after news of a big data breach, instead of one password at a time.
What the audit looks for
- In data breaches: the password is in Have I Been Pwned’s Pwned Passwords collection of passwords from real breaches, which attackers try first. NIST’s Digital Identity Guidelines (SP 800-63B-4, §3.1.1.2) require services to refuse such passwords and to force a change when there is evidence of compromise.
- Reused: the same password on two or more accounts (one account saved under two addresses of the same site does not count). One leak then opens every account in the group.
- Weak: zxcvbn scores the password 2 or less out of 4 — fewer than 100 million guesses, so it falls within hours if a site’s password database is stolen. Very weak passwords (0–1) fall even to guessing on a sign-in page without a rate limit, and count more.
- Similar to another: the same base with other digits, symbols or l33t letters (Summer2023! and summer2024), the variations cracking tools try first.
- Plain http address: the saved sign-in address does not use https, so the password may have been sent unprotected.
- Old: only when the export records dates (Firefox, KeePassXC, Proton Pass). An old password is worth changing if the site has had a breach since; otherwise NIST advises against changing passwords on a schedule.
Why e-mail comes first
Whoever gets into your e-mail can reset the passwords of almost every other account, so the UK’s National Cyber Security Centre advises a strong password for e-mail that is used nowhere else (NCSC). The fix list puts accounts at the big e-mail services first, and marks a reused e-mail password Fix now even when it has not leaked.
How the breach check keeps passwords private
Each password is hashed with SHA-1 in your browser. Only the first 5 of its 40 hex characters are sent to api.pwnedpasswords.com, which answers with every breached hash that starts with them — hundreds of them, padded with decoy lines (always counted 0) so that the size of the answer does not give the prefix away — and the rest of the hash is compared on your device (Have I Been Pwned API). Passwords that share a prefix are checked with one request. You can switch the check off; strength, reuse and the other checks then run without any request.
What the free preview shows
Without a pass, every count at the top is shown in full — accounts, Fix now, in breaches, reused, weak, similar, plain http, old and no problem found — so you can see how healthy the file is. The fix list and the list of reused-password groups show their first half (up to 10 rows each), and a file with a single account shows its row with the results hidden. The printed report and the CSV unlock with a Pro pass.
Limitations
- Chrome’s Password Checkup and most password managers already warn about passwords found in breaches; this page adds the whole-file view, the order of fixing and a report without passwords.
- E-mail addresses are not searched in breach lists: that search needs a paid key from Have I Been Pwned. Use haveibeenpwned.com for your addresses.
- Only what the export contains is checked: passkeys, cards, notes and items a password manager leaves out of its CSV are not audited.
- Strength is an estimate of how guessable a password is, not a guarantee; a strong password that leaked is still unsafe.
- MySmartCoPilot does not store, sync or manage passwords; use a password manager to change and keep them.
- Up to 20,000 passwords and a 10 MB file per audit.
Privacy
The file is read into this tab’s memory only — never uploaded, never stored, never shown — and is gone when you press Clear everything or leave the page. For the breach check only the first 5 characters of each password’s SHA-1 hash are sent, to Have I Been Pwned. The report and the CSV contain sites, user names and advice, never a password.
Frequently asked questions
What do I get without a pass?
Without a pass, Password Health Audit (Check an Exported Password File) shows every count, with the first half of the fix list and of the reused-password groups (up to 10 rows each). Until you unlock it, the result can’t be downloaded or printed. A Pro, Premium or Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
Is it safe to open my password file here?
The file is read by your browser and kept in memory only: it is not uploaded, not stored and no password is shown on the page. The only request about your passwords is the breach check, which sends the first 5 characters of each SHA-1 hash — shared by hundreds of other breached passwords — and you can switch it off.
Which exports does it read?
CSV files from Chrome and other Chromium browsers, Firefox, Apple Passwords and Safari, Bitwarden, 1Password, LastPass, KeePassXC, Proton Pass, Dashlane and others: the columns are found by their headings. If a file has no “password” heading (some managers write none), choose the columns yourself. Other formats — 1Password’s .1pux, a KeePass .kdbx database, an encrypted JSON export — cannot be read; export a CSV instead.
What should I fix first?
Follow the order of the list: passwords in breaches and reused e-mail passwords (Fix now), then reused and very weak ones (Fix soon), then weak and similar ones. Change each to a long random password that you use only once, and turn on two-step verification for e-mail and banking.
Why is a password marked “Similar to another”?
It is the same base as another of your passwords with a few characters changed, such as Summer2023! and summer2024. Cracking tools apply exactly these changes to leaked passwords, so variations protect little more than reuse.
What does the Change password button do?
It opens https://<the site>/.well-known/change-password in a new tab: the address the W3C draft A Well-Known URL for Changing Passwords defines, which a site that supports it sends on to its own password page. Nothing from your file is sent. Sites that do not support the address show another page or an error; then sign in and open the site’s security settings.
Should I change all my old passwords?
No. NIST’s guidelines advise against changing passwords on a schedule; change one when there is a reason — it leaked, it is reused or weak, or the site was breached after you set it. The page marks old passwords as “Check”, the lowest priority.
Can I check my e-mail address in breaches too?
Not here: Have I Been Pwned’s search by e-mail address needs a paid key and must credit the service. You can search your addresses on haveibeenpwned.com itself, and check single passwords with the Pwned Password Checker.
What do I do with the file afterwards?
Delete it and empty the Bin or Trash, and delete any copy you e-mailed or synced to the cloud. Firefox, Apple Passwords, Bitwarden and 1Password all warn that their exports hold the passwords in readable text and advise deleting the file after use.