Automated LastPass Password Health Reports
Every Monday, WebRun signs in to LastPass, reads the security dashboard for weak, reused, and old passwords, writes one row per flagged login into a Google Sheets tracker with its site and owner, and sends you a short Telegram list of the accounts to fix first.
How do I keep track of weak and reused passwords in LastPass?
WebRun reviews your LastPass security dashboard every Monday, capturing the logins flagged as weak, reused, or long unchanged. It tracks each one in Google Sheets with the site and reason, then sends a Telegram fix list, naming sites but never passwords, so risky credentials get rotated instead of forgotten.
- Weak and reused logins get a named owner and a due week
- Items lingering over a month are called out by name
- Password values never leave the vault
Built for IT administrators · security teams · small business owners · operations managers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.lastpass.comin a real browser with your saved login - no setup, no API keys. -
1
LastPass - read the security dashboard
WebRun opens LastPass to read the security dashboard. - Sign in to LastPass and open your security dashboard
- Read the logins flagged as weak, reused, or not changed in a long time
- Capture the site name, the username, and the reason it was flagged
- Note which flagged logins are shared with other people
Done when Every flagged login has a site, a username, and a reason.
-
2
Google Sheets - track every flagged login
WebRun opens Google Sheets to track every flagged login. - Open your password health tracker in Google Sheets
- Add or update one row per flagged login with site, username, reason, and the date flagged
- Mark rows as fixed when the login no longer appears on the dashboard
- Record how many weeks each item has stayed on the list
Done when The Google Sheets tracker matches this week's LastPass dashboard.
-
3
Telegram - send the fix list
WebRun opens Telegram to send the fix list. - Send a short Telegram summary with the counts of weak, reused, and old logins
- List the top accounts to fix first, naming the site but never the password
- Call out anything that has been on the list for more than a month
- Leave changing any password to a person. WebRun never edits a vault entry
Done when You have this week's password fix list on Telegram.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does it ever copy or send my actual passwords?
No. WebRun records only the site name, the username, and the reason a login was flagged. Password values are never read into the sheet, never put in a Telegram message, and never leave your vault.
Will it change or reset any passwords?
No. It cannot edit, rotate, delete, or share a vault entry. Every change is made by a person in LastPass. WebRun only produces the list of what needs attention.
How do I know something got fixed?
The dashboard is re-read every Monday, so any login that no longer appears is marked fixed in the Google Sheets tracker and drops off the Telegram list without you telling it.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.