Best Password Managers of 2026 (No Fake Reviews): Tested by a Cybersecurity Manager

Mefat Shabani

The problem

Password manager reviews are loaded with affiliate spam. Search “best password manager” and you find the same tools pushed by the same accounts. Lars Lofgren documented how Reddit moderators insert affiliate links into top comments and then sell their aged accounts to marketers. In one product recommendation thread he found five separate affiliate spammers.

Password manager threads follow the same pattern. The same usernames recommend NordPass or LastPass across  r/privacy, r/cybersecurity and r/software, with links that redirect through affiliate networks.

The commission rates explain most of it. NordPass, Dashlane and 1Password pay affiliates in the range of 30 to 40 percent. Keeper accepts only a small share of affiliate applicants and keeps its rates low. You can guess which ones appear on more lists.

The worst part is that most people pick a manager based on which one has the nicest website, then discover eighteen months later that the export option is a plain CSV file, or that the 2FA codes they stored were never actually protected the way they assumed.

The Answer

I have tested 15 password managers over what I can say my first decade working in cybersecurity, fully remote, on Windows, macOS, iOS and Android. This spreadsheet covers what you actually want to know: breach histories, audit dates and firms, TrustPilot complaint patterns, real renewal pricing rather than promotional rates, and which features matter for someone setting up their first vault.

Testing method: each manager imported the same 291-credential vault, then used as the daily driver for at least two weeks. Autofill tested against banking, government and e-commerce sites, not just simple logins.

Password Managers List

Online Security Hub
Compare all 15

Included or strongPartial or add-onNot available or weak

Comparison of 15 password managers across 86 attributes including encryption, audits, breach history, features, pricing and support. Verified 4 September 2026 by Mefat Shabani.
AttributeKeeperBitwarden1PasswordProton PassRoboFormLastPassNordPassDashlaneApple PasswordsGoogle Password MgrEnpassSticky PasswordKeePassXCNorton PMZoho Vault
PlanPersonalPremiumIndividualPass PlusPremiumPremiumPremiumAdvancedFreeFreeIndividualPremiumFreeFree/Norton 360Standard
Cheapest Paid Plan (per month, billed yearly)$4.37$1.65$3.99$2.99$2.49 ($0.99 first year)$3$1.99 (1-yr, first term)$4.99FreeFree$1.99$3.33FreeFree$0.90
Ownership/Parent CompanyKeeper Security Inc.Bitwarden Inc.AgileBits Inc.Proton AG (Switzerland)Siber Systems Inc.LastPassNord SecurityDashlane Inc.Apple Inc.Google/Alphabet Inc.Sinew Software SystemsLamantine SoftwareOpen Source CommunityGen Digital (NortonLifeLock)Zoho Corporation
Encryption AlgorithmAES-256AES-256AES-256AES-256AES-256AES-256XChaCha20AES-256AES-256AES-256AES-256 + SQLCipherAES-256AES-256/ChaCha20/TwofishAES-256AES-256
Encryption Strength256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit256-bit
Zero-Knowledge ArchitectureYesYesYesYesYesYesYesYesYesYesYesYesYesYesYes
Security AuditsSOC 2 Type 2, ISO 27001/17/18, FedRAMP HighCure53 (annual)Multiple (Cure53, SOC2)Cure53Secfault SecurityMultipleCure53SOC2 Type II, ISO 27001InternalInternalNo public auditNo public auditCommunity reviewedInternalRegular third-party
Latest Audit DateAnnual pentests (reports under NDA)2025 (annual, public)2025 (SOC 2 + pentests, public)2024 (Cure53, public)Feb 20252024Feb 20252025 (SOC 2 Type II)N/AN/AN/ANone publishedN/AN/A2024
Open SourceNoYes (Full)NoYes (Full)NoNoNoPartial (mobile)NoNoPartialNoYes (Full)NoNo
Data Breach HistoryNoneNoneNone (2023 Okta incident, no vault data)NoneNoneYes (2022 vault theft)NoneNoneNoneNoneNoneNoneNone2023 credential stuffingNone
Passkey SupportYesYesYesYesYesYesYesYesYesYesYesNoVia pluginsYesYes
Passwordless LoginYesYesYesYesYesYesYesYesYesYesYesNoNoNoYes
Unlimited Passwords (Free)No (10 records only)YesNo free planYesYes (1 device)Yes (1 device type)YesNo (discontinued Sep 2025)YesYesYes (Desktop)Yes (1 device)YesYesYes
Unlimited Devices (Free)No (mobile only)YesNo free planYesNoNoNo (1 device)NoYes (Apple devices)YesNo (25 items mobile)NoYesYesYes
Password GeneratorYesYesYesYesYesYesYesYesYesYesYesYesYesYesYes
AutofillYesYesYesYesYesYesYesYesYesYesYesYesVia plugins/XCYesYes
Form FillingAdvancedBasicYesBasicYesYesBasicYesYesYesYesYesVia pluginsYesNo
Secure NotesYesYesYesYesYesYesYesYesYesNoYesYesYesYesYes
Credit Card StorageYesYesYesYesYesYesYesYesYes (Apple Pay)Yes (Google Pay)YesYesVia custom fieldsYesYes
ID Document StorageYesYesYesYesYesYesYesYesNoNoYesYesYesYesYes
File AttachmentsYes (add-on)Yes (Premium, 1GB)Yes (1GB)Yes (Plus, 10GB)YesYes (1GB)Yes (Premium, 3GB)Yes (1GB)NoNoYesNoYesNoYes
Emergency AccessYes (add-on)YesNoYes (Plus)YesYesYesYesNoNoNoYesNoNoYes
Secure SharingYesYesYesYesYesYesYesYesYes (AirDrop)Yes (Family)YesYesNoNoYes
Password Health CheckYesYesYes (Watchtower)YesYesYesYesYesYesYesYesYesVia pluginsYesYes
Dark Web MonitoringAdd-on ($19.99/yr)No (Premium)Yes (Watchtower)YesYesYesYesYesNoNoNoYesNoWith Norton 360Yes (Enterprise)
Data Breach ScannerYesYesYesYesYesYesYesYesYesYes (Checkup)YesYesNoWith Norton 360Yes
TOTP AuthenticatorYesYesYesYesYesYesYesYesYesNoYesNoVia plugins/XCNoYes
Email Masking/AliasesNoNoNoYes (unlimited)NoNoYesNoYes (Hide My Email)NoNoNoNoNoNo
VPN IncludedNoNoNoNoNoNoNoYes (Premium)NoNoNoNoNoWith Norton 360No
Travel ModeNoNoYes (Travel Mode)NoNoNoNoNoNoNoNoNoNoNoNo
Offline AccessYesYesYesYesYesYesYesYesYesPartialYes (Local)YesYes (Local)YesYes
WindowsYesYesYesYesYesYesYesYesYes (iCloud)Yes (Chrome)YesYesYesYesWeb only
macOSYesYesYesYesYesYesYesYesYesYes (Chrome)YesYesYes (XC)YesWeb only
LinuxYesYesYesYesYesYesYesNoNoYes (Chrome)YesNoYes (XC)NoWeb only
iOSYesYesYesYesYesYesYesYesYesYesYesYesVia portsYesYes
AndroidYesYesYesYesYesYesYesYesNoYesYesYesVia portsYesYes
Chrome ExtensionYesYesYesYesYesYesYesYesYesYes (built-in)YesYesVia plugins/XCYesYes
Firefox ExtensionYesYesYesYesYesYesYesYesNoNoYesYesVia XCYesYes
Safari ExtensionYesYesYesYesYesYesYesYesYesNoYesYesNoYesYes
Edge ExtensionYesYesYesYesYesYesYesYesYesNoYesYesVia XCYesYes
Web VaultYesYesYesYesYesYesYesYesiCloud.compasswords.google.comNoYesNoYesYes
SSO IntegrationYesYesYesYesYesYesYes (Business)YesNoVia WorkspaceYesYesNoNoYes
SCIM ProvisioningYesYesYesYesNoYesYes (Enterprise)YesNoNoNoNoNoNoYes
Admin ConsoleYesYesYesYesYesYesYesYesNoVia WorkspaceYesYesNoNoYes
Activity Logs/AuditYesYesYesYesYesYesYesYesNoVia WorkspaceYesYesNoNoYes
Role-Based AccessYesYesYesYesYesYesYesYesNoVia WorkspaceNoYesNoNoYes
Directory IntegrationYesYesYesNoYesYesYesYesNoVia WorkspaceNoNoNoNoYes
Group ManagementYesYesYesYesYesYesYesYesNoNoNoYesNoNoYes
Custom Security PoliciesYesYesYesYesYesYesYesYesNoNoNoNoNoNoYes
Master PasswordYesYesYesYesYesYesYesYesYesGoogle accountYesYesYesYesYes
Biometric LoginYesYesYesYesYesYesYesYesYes (Face/Touch ID)YesYesYesNoYesYes
Hardware Key (FIDO2/YubiKey)YesYesYesYesYesYesYesYesYesYesYesNoYesNoYes
Authenticator App 2FAYesYesYesYesYesYesYesYesYesYesYesYesVia pluginsYesYes
SMS 2FAYesNoNoNoYesYesNoNoNoYesNoNoNoYesNo
Email 2FAYesYesNoNoYesYesYesNoNoYesNoYesNoYesYes
Free PlanVery limitedYes (robust)NoYes (robust)Yes (limited)Yes (limited)Yes (limited)No (discontinued)Fully freeFully freeDesktop onlyYes (limited)Fully freeYesYes (robust)
Individual (Monthly)Annual onlyAnnual only$4.99$4.99Annual onlyAnnual onlyNot sold (1-yr/2-yr only)Annual onlyFreeFreeAnnual onlyAnnual onlyFreeFree$1
Individual (Annual/mo)$4.37$1.65$3.99$2.99$2.49 ($0.99 first year)$3$1.99 (1-yr), $1.49 (2-yr)$4.99FreeFree$1.99$3.33FreeFree$0.90
Individual (billed per year)$52.45$19.80$47.88$35.88$29.88 ($11.90 first year)$36$23.88 first year$59.88FreeFree$23.99 (or $99.99 lifetime)$39.99 (or $199.99 lifetime)FreeFree$10.80
Renewal Price (Individual/yr)$52.45$19.80$47.88$35.88$29.88$36$35.88$59.88FreeFree$23.99$39.99FreeFree$10.80
Intro Discount vs RenewalPromos to 50% off first yearNoneNoneUp to 50% off (promo)60% off first yearNone33% off first yearUp to 50% off first year (promo)N/AN/ASeasonal onlyLifetime often 60% to 80% offN/AN/ANone
Family Plan (Annual/mo)$8.57$3.99$5.99$4.99$3.98 ($1.59 first year)$4$3.69 (1-yr), $2.79 (2-yr)$7.49FreeFree$3.99N/AFreeN/AN/A
Family Users565656610N/AN/A6N/AN/AN/AN/A
Teams/Business (per user/mo)$3.75 ($2 Starter)$4 (Teams), $6 (Enterprise)$7.99$1.99 (Essentials)$3.33$4.25 (Teams), $7 (Business)$1.79 (Teams), $3.59 (Business)$8 ($4 Credential Protection)N/AVia Workspace$2.99 ($9.99/mo flat for 10 users)$2.50FreeN/A$0.90 to $7.20
Enterprise PlanYesYesYesYesYesYesYesYesNoVia WorkspaceYesYesFreeNoYes
Money-Back Guarantee30-day trial (no refund)None (free tier instead)14-day trial30 days30 days30 days30 days30 days (14-day trial)N/AN/AFree tier; 30-day business trial30 daysN/A60 days15-day trial
Price Last VerifiedSep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026Sep 4, 2026
Import from BrowsersYesYesYesYesYesYesYesYesYesYesYesYesVia pluginsYesYes
Import from Other PMsYesYesYesYesYesYesYesYesYesYesYesYesYesYesYes
Export OptionsMultipleMultipleMultipleCSVMultipleMultipleCSVMultipleCSVCSVMultipleMultipleMultipleCSVMultiple
Self-Hosting OptionNoYesNoNoYes (local)NoNoNoNoNoYes (Local only)NoYes (Local only)NoNo
24/7 SupportYes (Business)NoNoNoYesNoNoYesYesYesNoNoNoYesNo
Live ChatYesNoNoNoYesNoYesYesYesNoNoYesNoYesNo
Phone SupportYes (Business)NoNoNoYesNoNoNoYesNoNoNoNoYesNo
Email SupportYesYesYesYesYesYesYesYesYesYesYesYesCommunityYesYes
Knowledge BaseYesYesYesYesYesYesYesYesYesYesYesYesYesYesYes
TrustPilot4.2/54.1/54.5/54.5/54.6/51.6/54.0/54.3/5N/AN/A3.8/54.2/5N/A3.5/54.0/5
G2 Rating4.6/54.6/54.7/54.4/54.5/54.4/54.5/54.5/5N/AN/A4.2/54.0/54.5/54.0/54.4/5
Capterra4.6/54.7/54.7/54.5/54.6/54.3/54.6/54.5/5N/AN/A4.3/54.3/54.5/54.0/54.5/5
Founded/Launched201120162006202320002008201920122011/2024201520142001200320162013
HeadquartersChicago, ILSanta Barbara, CAToronto, CanadaGeneva, SwitzerlandFairfax, VABoston, MAPanama/LithuaniaParis, France / NYCCupertino, CAMountain View, CAIndiaCzech RepublicGermany (original)Tempe, AZChennai, India
Users (Estimated)1M+10M+15M+2M+ (Pass)6M+30M+15M+15M+MillionsMillionsUnknown2M+UnknownUnknown100K+ teams
Common Complaint #1Add-ons increase costUI less polishedNo free planNewer productUI dated2022 data breachFree plan single deviceHigher price pointApple ecosystem onlyChrome-centricNo cloud backup optionNo Linux supportSteep learning curveBasic featuresNo desktop app
Common Complaint #2Repriced twice in 2026 (now $52.45/yr)Premium doubled to $19.80 (Jan 2026)Price up 33% (Mar 2026)2FA and sharing need PlusFewer advanced featuresICO £1.2M fine (2025)Dual login processFree plan discontinuedLimited cross-platformPrivacy concernsMobile limitationsLess modern UINo cloud sync built-inUpsells to Norton 360UI outdated
Common Complaint #3US jurisdictionLimited customer supportNo phone supportNo live chatLess known brandOngoing crypto theft linkedNo phone supportNo Linux appFewer advanced featuresNo secure notesNo public auditsSmaller brand awarenessUI not modernNo password sharingCan't import Safari
onlinesecurityhub.org

Password Managers I Recommend

  • Keeper is the one I use, and I switched to it in 2021 after testing Bitwarden, 1Password and LastPass. It is not the cheapest option, but the built-in TOTP authenticator and the autofill reliability are why I stayed. When I log into a site with 2FA enabled, Keeper fills the password and the six-digit code, or the passkey if the site supports it. The browser extension scans 2FA QR codes directly from the desktop instead of making you reach for your phone. Keeper was among the first managers to implement passkey storage protected by biometrics or a PIN across platforms. One-Time Share lets you send a credential to someone who does not have a Keeper account, offline access works without a connection, and the company holds SOC 2 and ISO 27001 with zero security incidents in its history. EU data centres are now available, which matters if you want your vault inside GDPR jurisdiction rather than under US law. The downsides are real: BreachWatch dark web monitoring costs an extra $20 a year and should be included in paid plans, the code is closed source so you cannot audit it yourself, there is no email alias feature, and it is a US company even with EU storage. If you want one thing that works every day without you thinking about it, this is the one.
    Keeper auto filling

  • Bitwarden changed my mind about free password managers. The free tier gives you unlimited passwords on unlimited devices, which nothing else matches. I imported 291 passwords from NordPass in about 40 seconds. The interface looks dated next to Keeper or 1Password, but it is fully functional, and the search stays fast with hundreds of entries. What matters more is that Bitwarden is completely open source, with regular third-party audits from Cure53, so the security claims are verifiable rather than asserted. Folders and collections handle the separation between personal and work accounts without paying extra, the password generator does passphrases as well as random strings, and self-hosting is available if you want full control. Premium is $10 a year, cheaper than every competitor. The problems are autofill bugs on Android and Chromium browsers, no dark web monitoring on the free plan, and US jurisdiction, though Bitwarden does maintain data processing agreements and lets you choose a server region. If you are not going to pay for a password manager, use this one and stop looking.
    Bitwarden free import

  • 1Password is the most polished product in this list and the only reason I would recommend it over Bitwarden is Travel Mode. It temporarily removes sensitive vaults from your devices when you cross a border, so if customs asks you to unlock your phone, the work credentials are not there to find. That is genuinely useful and nobody else does it properly.travel mode
    Watchtower monitors password health and breach exposure, autofill is reliable across platforms, and the family plan at $4.49 a month for five users is fair value. Past that, my enthusiasm runs out. The email alias feature only works with Fastmail, which makes it useless unless you are already a Fastmail customer, and Proton Pass gives you unlimited aliases with any email setup. The Secret Key requirement for new device logins is a hassle to store safely. There is no free plan at all, only a 14-day trial. The company is in Canada, a Five Eyes country. You are paying more than Bitwarden for polish rather than function, and for daily use I still prefer Keeper’s TOTP handling.

  • Proton Pass comes from the company behind ProtonMail and ProtonVPN, and Swiss jurisdiction gives it stronger legal protection than any US-based alternative. The standout feature is unlimited hide-my-email aliases. You generate a unique address for every signup, and if that site is breached or sells your data, you disable the alias and the spam stops. The Pass plus SimpleLogin lifetime deal at $199 never expires, which is good value if aliases are your priority. It is open source and audited, and a July 2025 Cure53 audit found only a low-severity issue where locked vaults kept passwords in memory for up to 30 minutes on Firefox, which Proton fixed immediately. The problem I hit in testing was site compatibility. Some websites refuse to work with Proton Pass at all, mainly financial and e-commerce sites, which are exactly the logins where you want autofill working. Keeper handles those same sites, and where neither manager can see the login fields, Keeper at least gives you a button to force the credentials in. Proton Pass has no fallback, and support requests about site compatibility have taken months. You also cannot create custom sections or extra fields. If privacy and aliases are your main concern, it is worth it. If not, the others are better daily drivers.

  • RoboForm has been around since 1999 and it fills complex forms better than anything else I have tested apart from Keeper. Government forms, insurance applications, multi-field checkouts with separate shipping and billing addresses: it gets them right where 1Password, NordPass and Bitwarden all stumble. If you regularly deal with tax documents, medical paperwork, visa applications or job applications, that alone justifies it despite the dated interface. TOTP is built in, local-only storage is available if you do not want cloud sync, and the Security Center flags weak and reused passwords. The history is worth knowing. In 2014 RoboForm was encrypting and decrypting server-side, the client-side JavaScript had bias in its random number generator, the TLS configuration was vulnerable to POODLE, and SSL Labs rated them a C. That was bad. They rebuilt the architecture, removed server-side decryption, and the security model now matches modern competitors. I mention it because they responded to criticism rather than ignoring it, which is more than most vendors do. The remaining downsides are a clunky mobile app, limited sharing, no email aliases and no dark web monitoring on lower plans.

Password Managers I Do Not Recommend

  • LastPass is the clearest avoid on this list. In 2022, attackers stole encrypted vault backups belonging to roughly 30 million users. Four years later people are still losing money. TRM Labs traced $35 million in stolen cryptocurrency through late 2025. The FBI linked a $150 million theft from Ripple co-founder Chris Larsen to the same breach. Security Alliance estimated total losses at $250 million as of May 2024, and individual incidents include $4.4 million in October 2023 and $5.36 million in December 2024. The UK Information Commissioner’s Office fined LastPass £1.2 million for inadequate security. TRM Labs traced funds to Russian exchanges including Cryptex, which the US Treasury sanctioned in 2024 for receiving $51.2 million in ransomware proceeds. LastPass still has not told customers that credentials stored in Secure Notes may be exposed. If you ever stored cryptocurrency seed phrases, private keys or sensitive credentials in LastPass before August 2022, move those funds now, then change every password, then leave.

  • NordPass is heavily promoted by affiliates because Nord pays generous commissions, which is why you see it everywhere. After testing it I cannot recommend it. Load times are painfully slow on both the app and the extension, and I was stuck on loading screens for two to three minutes at a time. The autofill confuses itself with autogenerate on new password fields, tries to save random things like contact email fields on forms with no login at all, and rarely fires when you actually need it. More than once I accepted a generated password when creating an account and NordPass simply did not save it, which means a password reset and starting over. There is no built-in 2FA authenticator on the premium personal plan, which is difficult to defend in 2026 when Keeper, Bitwarden and RoboForm all include one. Reinstalling and switching networks changed nothing. The encryption is XChaCha20, the jurisdiction is Panama, and Cure53 audits it regularly, so the underlying security is not the issue. The product is. If you get it free with a paid Revolut plan, it is tolerable. Otherwise use Bitwarden for nothing or Keeper for a bit more.

  • Dashlane discontinued its free plan in September 2025, so the entry price is now $4.99 a month. The family plan is $7.49 a month against 1Password’s $4.49 for the same five users, and that premium is hard to justify when the functionality is comparable. The interface is polished and autofill works reliably, though not as well as Keeper or RoboForm. The bundled VPN is the only genuinely unusual thing here, and it is redundant if you already pay for NordVPN, Proton VPN or anything else. Dark web monitoring needs a higher tier. There is no scenario where Dashlane is the right answer unless the bundled VPN is exactly what you were shopping for.

  • Apple Passwords works well if every device you own is an Apple device, and falls apart the moment one is not. iCloud Keychain sync problems are well documented across Reddit and Apple’s own community forums: passwords that stop syncing between devices, entries reverting to older versions, the Windows iCloud app refusing authorisation for weeks. Users report changing their Apple ID password and re-authenticating every device just to get sync working again. There is no separate master password, so the vault is protected only by your device passcode or biometrics. The only export option is an unencrypted CSV file, and the process is buried, which is lock-in by design. macOS Sequoia made it worse by moving Keychain Access into a hidden system folder, removing it from the Dock and removing the ability to create new secure notes. There is no TOTP storage, no dark web monitoring, no secure sharing outside the ecosystem and no family sharing with non-Apple users.

  • Google Password Manager is free because you are the product. Google already has your search history, email contents, location history, YouTube activity and Chrome browsing data. Adding bank logins and medical portal credentials to that profile is a risk I will not take. It is not zero-knowledge, which means Google can technically decrypt your data under legal request, and because it is closed source there is no way to verify the security claims independently. TechRepublic’s 2025 review noted that the encryption methods are not clearly documented for users. In July 2024 a bug locked 15 to 17 million Windows users out of their passwords for around 18 hours. There is no secure sharing, no built-in TOTP storage, no emergency access, and your Google account becomes a single point of failure for everything you own.

  • Enpass sells itself on local storage and no forced subscription, which sounds good until you look at patch timing. Browser extensions are the main attack surface for password managers, and clickjacking, UI redressing and iframe manipulation have been documented for over a decade. At DEF CON 33 in August 2025, researcher Marek Tóth demonstrated DOM-based clickjacking against password manager extensions, where a single click on a malicious site can leak stored credentials, 2FA codes and card details by overlaying invisible elements over the autofill controls. You think you are dismissing a cookie banner. Tóth’s research tested 11 managers and found every one vulnerable to at least one vector, so this is not an Enpass-specific flaw. What separates them is response time. Keeper, NordPass, Proton Pass, RoboForm and Dashlane all patched before public disclosure. Enpass was listed as vulnerable at disclosure and was still patching afterwards, with protections inconsistent across platforms and browser versions according to Socket’s follow-up. That is the gap I care about in security software.

  • Sticky Password offers local storage, optional cloud sync and a lifetime licence, which will appeal if you hate subscriptions. Everything else is stuck around 2015. The interface is dated, autofill is clunky, vault search is slow and the mobile apps lag. There is no built-in TOTP authenticator, no emergency access and no passkey support. Scroll the changelog looking for the last meaningful feature and you will be scrolling for a while. It has never had a major breach, but that is the minimum bar, not an achievement. Security software in maintenance mode is a liability.

  • KeePass is a legitimate open-source manager with strong cryptography, and the software itself is not the problem. The distribution is. Attackers have bundled trojanised KeePass installers with malware and pushed them through unofficial download sites and search ads. If you download it from anywhere other than the official page and do not verify the file hash, you are gambling with your machine. For technical users who verify checksums and stick to official sources, KeePass is fine. For everyone else the risk is unnecessary when Bitwarden’s free tier does the same job with automatic updates and no verification step to forget.

  • Norton Password Manager ships with Norton 360 and is also available free as a standalone product. It handles basic password storage acceptably and nothing more. There is no built-in TOTP authenticator, no secure sharing, no emergency access, and import options are severely limited even against free competitors. The encryption is AES-256 with zero-knowledge architecture, so the fundamentals are sound, but it feels like an afterthought to Norton’s main products. Bitwarden’s free tier is better in every way that matters.

  • Zoho Vault is built for organisations inside the Zoho ecosystem, where it integrates well and has solid team management. For personal use it is wrong in every direction. The interface is designed for business administrators, with settings and tabs that mean nothing to an individual. Emergency access is only available on business plans. Autofill barely works beyond credentials, you cannot delete passwords shared with you, and Safari users cannot import at all. If your company already runs Zoho, fine. Otherwise there is no reason to be here.

Pricing and Renewal Comparison

Renewal pricing is where password managers behave worst, so check the second-year number before you buy, not the first.

Password manager pricing 2026: free tier, first-year price, renewal price, family plan, refund window and affiliate commission for 15 managers.
ManagerFree tierFirst yearRenews atFamily planTrial or refundAffiliate commission
BitwardenUnlimited passwords, unlimited devices$19.80 a year, $1.65 a monthSame, no increase published$47.88 a year for 6 users7-day trialNot published
KeeperVery limited$52.45 a year, $4.37 a monthSame, no increase published$112.23 a year for 5 users30-day refundRestricted programme, low rate
1PasswordNone$35.88 a year, $2.99 a monthStandard rate $3.99 a month$53.88 a year for 5 users14-day trialNot published
Proton PassYes, unlimited logins and devices€35.88 a year, €2.99 a monthStandard rate €4.99 a month€59.88 a year for 6 users30-day refundNot published
RoboFormUnlimited passwords, 1 device€19.90 first year€29.88, up 50 percent€31.95 then €47.75, 5 users30-day refund$2 per signup plus 25%
NordPassUnlimited passwords, 1 device€23.88 first year€35.88, up 50 percent€44.28 then €71.88, 6 users30-day refundNot published
EnpassDesktop only$14.39 first year$23.99, up 67 percent$35.99 then $47.99, 6 users14-day trialNot published
DashlaneNone since Sept 2025€47.16 a year, €3.93 a monthNot published€71.40 a year for 10 users14-day trialUp to 25%
LastPassYes, 1 device type€34.80 a year, €2.90 a monthNot published€46.80 a year for 6 users30-day trialNot published
Sticky PasswordYes, no sync or sharing€29.95 first year€39.95 standard rateNot offered30-day refundNot published
Zoho VaultYes, personal use€10.80 a year per user, businessSame, no increase publishedNot offered15-day trialNot published
Norton PMFully freeFreeFreeBundled with Norton 36060-day refundNot published
KeePassXCFully freeFreeFreeFreeNot applicableNone, open source
Apple PasswordsFully freeFreeFreeFreeNot applicableNone
Google PMFully freeFreeFreeFreeNot applicableNone

Prices taken from each vendor's own pricing page in September 2026. Currency is shown as the vendor displays it to a European visitor, so some figures are USD and some EUR and they are not directly comparable. RoboForm, NordPass and Dashlane display prices excluding VAT. One-time options not shown in the table: Enpass lifetime $79.99, Enpass three-year $33.59, Sticky Password lifetime €79.95. Affiliate rates appear only where a vendor publishes one.

Security, Audits and Breach History

This is the table most roundups will not publish, because it makes several popular products look bad.

Password manager security comparison 2026: jurisdiction, open source status, audits, breach history and DEF CON 33 clickjacking patch timing for 15 managers.
ManagerJurisdictionOpen sourceIndependent auditsLatest auditBreach historyClickjacking fixTiming vs disclosure
KeeperUS, EU data centres availableNoSOC 2, ISO 270012024NoneFixed 17.2.0, 25 Jul 202515 days before
RoboFormUSNoSecfault SecurityFeb 2025Architecture issues 2014, rebuiltFixed 9.7.6, 25 Jul 202515 days before
DashlaneFrance and USPartial, mobileSOC 2 Type II, ISO 270012024NoneFixed v6.2531.1, 1 Aug 20258 days before
NordPassPanama and LithuaniaNoCure53Feb 2025NoneFixed 5.13.24, 15 Feb 202418 months before
Proton PassSwitzerlandYes, fullSEC Consult, Cure53Jul 2025NoneFixed 1.31.6Before disclosure
EnpassIndiaPartialNo public auditNot applicableNoneFixed 6.11.6, 13 Aug 20254 days after
BitwardenUS, region choice availableYes, fullCure53, Insight Risk2024NoneFixed 2025.8.2, 31 Aug 202522 days after
Apple PasswordsUSNoInternal onlyNot applicableNoneFixed 3.1.30, 21 Oct 202573 days after
KeePassXCGermany, communityYes, fullCommunity reviewedNot applicableNoneFixed 1.9.11, 26 Nov 2025109 days after
1PasswordCanada, Five EyesNoCure53, SOC 2Feb 2025NoneStill unpatched as of 14 Jan 2026Not fixed
LastPassUS, Five EyesNoMultiple20242022, roughly 30M vaults stolenStill unpatched as of 14 Jan 2026Not fixed
Zoho VaultIndiaNoRegular third-party2024NoneNot testedNot tested
Google PMUS, Five EyesNoInternal onlyNot applicableJul 2024 lockout, 15 to 17M usersNot testedNot tested
Norton PMUS, Five EyesNoInternal onlyNot applicableNoneNot testedNot tested
Sticky PasswordCzech RepublicNoNo public auditNot applicableNoneNot testedNot tested

Clickjacking data from Marek Toth, DOM-based Extension Clickjacking, last updated 14 January 2026. All 11 managers he tested were vulnerable in default configuration. Vendors were notified in April 2025 and had more than 120 days before public disclosure at DEF CON 33 on 9 August 2025. 1Password and LastPass both classified the report as informative.

10 Tips for Choosing a Password Managers

  1. Check whether TOTP is included, and on which plan. Storing your 2FA codes in the same vault as your passwords is a trade-off, and I will come back to that, but if you want it, check the plan. NordPass does not include it on the premium personal plan. Bitwarden puts it behind the $10 premium tier. Keeper, 1Password and RoboForm include it.
  2. Calculate the three-year cost, not the first-year price. Password managers are less aggressive on renewals than antivirus vendors, but the pattern exists. Take the promotional price, add two renewals, and compare that number instead. Bitwarden at $10 a year flat wins this comparison against almost everything.
  3. Prefer open source, but check that it is actually audited. Open source means researchers can inspect the code. It does not mean anyone has. Bitwarden and Proton Pass both publish third-party audits, most recently from Cure53. If a vendor claims open source and cannot point you to an audit report with a firm name and a date, treat the claim as marketing.
  4. Check the breach history and how the company responded. LastPass is the obvious case, but the useful signal is not that a breach happened. It is what they did afterwards. LastPass has still not warned customers about credentials in Secure Notes, four years on. RoboForm had a genuinely bad architecture in 2014, rebuilt it, and said so publicly. Those two responses tell you different things about the companies.
  5. Check extension patch timing after a public disclosure. After Marek Tóth’s DEF CON 33 research, some vendors had fixes out before the talk and some were still working on it months later. Search for the product name plus the vulnerability and look at the dates. This is the single best proxy for how seriously a vendor takes security work that is not visible to customers.
  6. Test the import before you commit to anything. Every manager claims easy import. Try it inside the trial window with your real vault, then check that TOTP seeds, secure notes, custom fields and attachments all survived. Codes and notes are the usual casualties, and you will not notice until you need them.
  7. Test autofill on the sites you actually use, especially banks. This is where products separate. Simple logins work everywhere. Bank portals, government forms and multi-step checkouts do not. Proton Pass failed on financial sites in my testing while Keeper handled the same sites, and no feature list would have told you that.
  8. Check the export path before you go in. Assume you will leave one day. Apple’s only export is an unencrypted CSV and the option is buried. Zoho Vault will not let Safari users import at all. Before you move hundreds of credentials into a product, confirm you can get them out in a usable, encrypted form.
  9. Do not use your browser’s built-in manager for financial accounts. Google Password Manager is not zero-knowledge, which means Google can decrypt your vault under legal request. Apple Passwords has no separate master password. Both are fine for low-value logins and wrong for anything involving money or health data. If you use nothing else, at least separate those.
  10. A password manager does not fix a weak master password. Everything in the vault sits behind that one credential and the second factor protecting it. Use a long passphrase you have never used anywhere else, enable 2FA on the manager itself, and write the recovery kit down on paper stored somewhere physical. Zero-knowledge encryption means the vendor genuinely cannot help you if you lose it.

Still not sure which one?

Leave me a comment with what you need: how many devices, whether you want TOTP in the same vault, whether you need family sharing, whether you are in the EU and care about where the data sits, and your budget. I will point you to the right one.

Thanks,
Mefat

Share This Article

You Might Also Find Interesting:

Leave a Comment

I started reviewing password managers in 2020 while searching for the right one for my own use. After years of testing and daily use, as of 2026, I only recommend two: Keeper as the best all-in-one solution, and Bitwarden as the best free option.

Get security drops!