BreachCheck by Pixelvault Labs
Check if a password has appeared in known data breaches — privately, using k-anonymity. Includes a secure password generator and strength meter. Nothing you type ever leaves your device.
Extension Metadata
Screenshots
About this extension
BreachCheck — has your password been breached?
Billions of passwords have leaked in data breaches. If yours is one of them, attackers can log in as you anywhere you reused it. BreachCheck tells you in one click — without ever exposing your password.
PRIVATE BY DESIGN (K-ANONYMITY)
Your password is hashed with SHA-1 on your device, and only the FIRST 5 characters of that hash are sent to the free HaveIBeenPwned Pwned Passwords API. The API returns ~800 candidate hashes; your device compares them locally and reports the result. The password — and even the full hash — never leaves your device. It is never stored, and the field is cleared after every check.
WHAT YOU GET
- One-click breach check against 15+ billion breached passwords
- Password generator: 12–32 characters, cryptographically random (crypto.getRandomValues), numbers/symbols toggles, click-to-copy
- Local strength meter: entropy-based, no libraries, no network
- Check history: date + outcome only (never the password), clearable
HONEST WORDING
"Not found" means no known breach contains the password — it is not a guarantee of safety. We never claim a password is "safe".
PERMISSIONS — MINIMAL
- storage: keeps your check history (outcome only) on your device.
- api.pwnedpasswords.com: the anonymous 5-character hash-prefix lookup.
No content scripts. No page access. No remote code. No accounts, no tracking, no analytics.
Free forever. Made by Pixelvault Labs.
Billions of passwords have leaked in data breaches. If yours is one of them, attackers can log in as you anywhere you reused it. BreachCheck tells you in one click — without ever exposing your password.
PRIVATE BY DESIGN (K-ANONYMITY)
Your password is hashed with SHA-1 on your device, and only the FIRST 5 characters of that hash are sent to the free HaveIBeenPwned Pwned Passwords API. The API returns ~800 candidate hashes; your device compares them locally and reports the result. The password — and even the full hash — never leaves your device. It is never stored, and the field is cleared after every check.
WHAT YOU GET
- One-click breach check against 15+ billion breached passwords
- Password generator: 12–32 characters, cryptographically random (crypto.getRandomValues), numbers/symbols toggles, click-to-copy
- Local strength meter: entropy-based, no libraries, no network
- Check history: date + outcome only (never the password), clearable
HONEST WORDING
"Not found" means no known breach contains the password — it is not a guarantee of safety. We never claim a password is "safe".
PERMISSIONS — MINIMAL
- storage: keeps your check history (outcome only) on your device.
- api.pwnedpasswords.com: the anonymous 5-character hash-prefix lookup.
No content scripts. No page access. No remote code. No accounts, no tracking, no analytics.
Free forever. Made by Pixelvault Labs.
Rated 0 by 0 reviewers
Permissions and data
Optional permissions:
- Access your data for api.pwnedpasswords.com
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 1.0.0
- Size
- 41.02 KB
- Last updated
- 5 days ago (Sep 27, 2026)
- Related Categories
- License
- All Rights Reserved
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection