The problem
Password manager reviews are loaded with affiliate spam. Search “best password manager” and you find the same tools pushed by the same accounts. Lars Lofgren documented how Reddit moderators insert affiliate links into top comments and then sell their aged accounts to marketers. In one product recommendation thread he found five separate affiliate spammers.
Password manager threads follow the same pattern. The same usernames recommend NordPass or LastPass across r/privacy, r/cybersecurity and r/software, with links that redirect through affiliate networks.
The commission rates explain most of it. NordPass, Dashlane and 1Password pay affiliates in the range of 30 to 40 percent. Keeper accepts only a small share of affiliate applicants and keeps its rates low. You can guess which ones appear on more lists.
The worst part is that most people pick a manager based on which one has the nicest website, then discover eighteen months later that the export option is a plain CSV file, or that the 2FA codes they stored were never actually protected the way they assumed.
The Answer
I have tested 15 password managers over what I can say my first decade working in cybersecurity, fully remote, on Windows, macOS, iOS and Android. This spreadsheet covers what you actually want to know: breach histories, audit dates and firms, TrustPilot complaint patterns, real renewal pricing rather than promotional rates, and which features matter for someone setting up their first vault.
Testing method: each manager imported the same 291-credential vault, then used as the daily driver for at least two weeks. Autofill tested against banking, government and e-commerce sites, not just simple logins.
Password Managers List
Compare all 15
Included or strongPartial or add-onNot available or weak
| Attribute | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Plan | Personal | Premium | Individual | Pass Plus | Premium | Premium | Premium | Advanced | Free | Free | Individual | Premium | Free | Free/Norton 360 | Standard |
| Cheapest Paid Plan (per month, billed yearly) | $4.37 | $1.65 | $3.99 | $2.99 | $2.49 ($0.99 first year) | $3 | $1.99 (1-yr, first term) | $4.99 | Free | Free | $1.99 | $3.33 | Free | Free | $0.90 |
| Ownership/Parent Company | Keeper Security Inc. | Bitwarden Inc. | AgileBits Inc. | Proton AG (Switzerland) | Siber Systems Inc. | LastPass | Nord Security | Dashlane Inc. | Apple Inc. | Google/Alphabet Inc. | Sinew Software Systems | Lamantine Software | Open Source Community | Gen Digital (NortonLifeLock) | Zoho Corporation |
| Encryption Algorithm | AES-256 | AES-256 | AES-256 | AES-256 | AES-256 | AES-256 | XChaCha20 | AES-256 | AES-256 | AES-256 | AES-256 + SQLCipher | AES-256 | AES-256/ChaCha20/Twofish | AES-256 | AES-256 |
| Encryption Strength | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit | 256-bit |
| Zero-Knowledge Architecture | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Security Audits | SOC 2 Type 2, ISO 27001/17/18, FedRAMP High | Cure53 (annual) | Multiple (Cure53, SOC2) | Cure53 | Secfault Security | Multiple | Cure53 | SOC2 Type II, ISO 27001 | Internal | Internal | No public audit | No public audit | Community reviewed | Internal | Regular third-party |
| Latest Audit Date | Annual pentests (reports under NDA) | 2025 (annual, public) | 2025 (SOC 2 + pentests, public) | 2024 (Cure53, public) | Feb 2025 | 2024 | Feb 2025 | 2025 (SOC 2 Type II) | N/A | N/A | N/A | None published | N/A | N/A | 2024 |
| Open Source | No | Yes (Full) | No | Yes (Full) | No | No | No | Partial (mobile) | No | No | Partial | No | Yes (Full) | No | No |
| Data Breach History | None | None | None (2023 Okta incident, no vault data) | None | None | Yes (2022 vault theft) | None | None | None | None | None | None | None | 2023 credential stuffing | None |
| Passkey Support | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Via plugins | Yes | Yes |
| Passwordless Login | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | Yes |
| Unlimited Passwords (Free) | No (10 records only) | Yes | No free plan | Yes | Yes (1 device) | Yes (1 device type) | Yes | No (discontinued Sep 2025) | Yes | Yes | Yes (Desktop) | Yes (1 device) | Yes | Yes | Yes |
| Unlimited Devices (Free) | No (mobile only) | Yes | No free plan | Yes | No | No | No (1 device) | No | Yes (Apple devices) | Yes | No (25 items mobile) | No | Yes | Yes | Yes |
| Password Generator | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Autofill | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Via plugins/XC | Yes | Yes |
| Form Filling | Advanced | Basic | Yes | Basic | Yes | Yes | Basic | Yes | Yes | Yes | Yes | Yes | Via plugins | Yes | No |
| Secure Notes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | Yes |
| Credit Card Storage | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (Apple Pay) | Yes (Google Pay) | Yes | Yes | Via custom fields | Yes | Yes |
| ID Document Storage | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | Yes | Yes | Yes | Yes | Yes |
| File Attachments | Yes (add-on) | Yes (Premium, 1GB) | Yes (1GB) | Yes (Plus, 10GB) | Yes | Yes (1GB) | Yes (Premium, 3GB) | Yes (1GB) | No | No | Yes | No | Yes | No | Yes |
| Emergency Access | Yes (add-on) | Yes | No | Yes (Plus) | Yes | Yes | Yes | Yes | No | No | No | Yes | No | No | Yes |
| Secure Sharing | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (AirDrop) | Yes (Family) | Yes | Yes | No | No | Yes |
| Password Health Check | Yes | Yes | Yes (Watchtower) | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Via plugins | Yes | Yes |
| Dark Web Monitoring | Add-on ($19.99/yr) | No (Premium) | Yes (Watchtower) | Yes | Yes | Yes | Yes | Yes | No | No | No | Yes | No | With Norton 360 | Yes (Enterprise) |
| Data Breach Scanner | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (Checkup) | Yes | Yes | No | With Norton 360 | Yes |
| TOTP Authenticator | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | Via plugins/XC | No | Yes |
| Email Masking/Aliases | No | No | No | Yes (unlimited) | No | No | Yes | No | Yes (Hide My Email) | No | No | No | No | No | No |
| VPN Included | No | No | No | No | No | No | No | Yes (Premium) | No | No | No | No | No | With Norton 360 | No |
| Travel Mode | No | No | Yes (Travel Mode) | No | No | No | No | No | No | No | No | No | No | No | No |
| Offline Access | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Partial | Yes (Local) | Yes | Yes (Local) | Yes | Yes |
| Windows | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (iCloud) | Yes (Chrome) | Yes | Yes | Yes | Yes | Web only |
| macOS | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (Chrome) | Yes | Yes | Yes (XC) | Yes | Web only |
| Linux | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | Yes (Chrome) | Yes | No | Yes (XC) | No | Web only |
| iOS | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Via ports | Yes | Yes |
| Android | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | Via ports | Yes | Yes |
| Chrome Extension | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (built-in) | Yes | Yes | Via plugins/XC | Yes | Yes |
| Firefox Extension | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | Yes | Yes | Via XC | Yes | Yes |
| Safari Extension | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | No | Yes | Yes |
| Edge Extension | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | Via XC | Yes | Yes |
| Web Vault | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | iCloud.com | passwords.google.com | No | Yes | No | Yes | Yes |
| SSO Integration | Yes | Yes | Yes | Yes | Yes | Yes | Yes (Business) | Yes | No | Via Workspace | Yes | Yes | No | No | Yes |
| SCIM Provisioning | Yes | Yes | Yes | Yes | No | Yes | Yes (Enterprise) | Yes | No | No | No | No | No | No | Yes |
| Admin Console | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Via Workspace | Yes | Yes | No | No | Yes |
| Activity Logs/Audit | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Via Workspace | Yes | Yes | No | No | Yes |
| Role-Based Access | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Via Workspace | No | Yes | No | No | Yes |
| Directory Integration | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | No | Via Workspace | No | No | No | No | Yes |
| Group Management | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | Yes | No | No | Yes |
| Custom Security Policies | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No | No | Yes |
| Master Password | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Google account | Yes | Yes | Yes | Yes | Yes |
| Biometric Login | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes (Face/Touch ID) | Yes | Yes | Yes | No | Yes | Yes |
| Hardware Key (FIDO2/YubiKey) | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | No | Yes |
| Authenticator App 2FA | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Via plugins | Yes | Yes |
| SMS 2FA | Yes | No | No | No | Yes | Yes | No | No | No | Yes | No | No | No | Yes | No |
| Email 2FA | Yes | Yes | No | No | Yes | Yes | Yes | No | No | Yes | No | Yes | No | Yes | Yes |
| Free Plan | Very limited | Yes (robust) | No | Yes (robust) | Yes (limited) | Yes (limited) | Yes (limited) | No (discontinued) | Fully free | Fully free | Desktop only | Yes (limited) | Fully free | Yes | Yes (robust) |
| Individual (Monthly) | Annual only | Annual only | $4.99 | $4.99 | Annual only | Annual only | Not sold (1-yr/2-yr only) | Annual only | Free | Free | Annual only | Annual only | Free | Free | $1 |
| Individual (Annual/mo) | $4.37 | $1.65 | $3.99 | $2.99 | $2.49 ($0.99 first year) | $3 | $1.99 (1-yr), $1.49 (2-yr) | $4.99 | Free | Free | $1.99 | $3.33 | Free | Free | $0.90 |
| Individual (billed per year) | $52.45 | $19.80 | $47.88 | $35.88 | $29.88 ($11.90 first year) | $36 | $23.88 first year | $59.88 | Free | Free | $23.99 (or $99.99 lifetime) | $39.99 (or $199.99 lifetime) | Free | Free | $10.80 |
| Renewal Price (Individual/yr) | $52.45 | $19.80 | $47.88 | $35.88 | $29.88 | $36 | $35.88 | $59.88 | Free | Free | $23.99 | $39.99 | Free | Free | $10.80 |
| Intro Discount vs Renewal | Promos to 50% off first year | None | None | Up to 50% off (promo) | 60% off first year | None | 33% off first year | Up to 50% off first year (promo) | N/A | N/A | Seasonal only | Lifetime often 60% to 80% off | N/A | N/A | None |
| Family Plan (Annual/mo) | $8.57 | $3.99 | $5.99 | $4.99 | $3.98 ($1.59 first year) | $4 | $3.69 (1-yr), $2.79 (2-yr) | $7.49 | Free | Free | $3.99 | N/A | Free | N/A | N/A |
| Family Users | 5 | 6 | 5 | 6 | 5 | 6 | 6 | 10 | N/A | N/A | 6 | N/A | N/A | N/A | N/A |
| Teams/Business (per user/mo) | $3.75 ($2 Starter) | $4 (Teams), $6 (Enterprise) | $7.99 | $1.99 (Essentials) | $3.33 | $4.25 (Teams), $7 (Business) | $1.79 (Teams), $3.59 (Business) | $8 ($4 Credential Protection) | N/A | Via Workspace | $2.99 ($9.99/mo flat for 10 users) | $2.50 | Free | N/A | $0.90 to $7.20 |
| Enterprise Plan | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Via Workspace | Yes | Yes | Free | No | Yes |
| Money-Back Guarantee | 30-day trial (no refund) | None (free tier instead) | 14-day trial | 30 days | 30 days | 30 days | 30 days | 30 days (14-day trial) | N/A | N/A | Free tier; 30-day business trial | 30 days | N/A | 60 days | 15-day trial |
| Price Last Verified | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 | Sep 4, 2026 |
| Import from Browsers | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Via plugins | Yes | Yes |
| Import from Other PMs | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Export Options | Multiple | Multiple | Multiple | CSV | Multiple | Multiple | CSV | Multiple | CSV | CSV | Multiple | Multiple | Multiple | CSV | Multiple |
| Self-Hosting Option | No | Yes | No | No | Yes (local) | No | No | No | No | No | Yes (Local only) | No | Yes (Local only) | No | No |
| 24/7 Support | Yes (Business) | No | No | No | Yes | No | No | Yes | Yes | Yes | No | No | No | Yes | No |
| Live Chat | Yes | No | No | No | Yes | No | Yes | Yes | Yes | No | No | Yes | No | Yes | No |
| Phone Support | Yes (Business) | No | No | No | Yes | No | No | No | Yes | No | No | No | No | Yes | No |
| Email Support | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Community | Yes | Yes |
| Knowledge Base | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| TrustPilot | 4.2/5 | 4.1/5 | 4.5/5 | 4.5/5 | 4.6/5 | 1.6/5 | 4.0/5 | 4.3/5 | N/A | N/A | 3.8/5 | 4.2/5 | N/A | 3.5/5 | 4.0/5 |
| G2 Rating | 4.6/5 | 4.6/5 | 4.7/5 | 4.4/5 | 4.5/5 | 4.4/5 | 4.5/5 | 4.5/5 | N/A | N/A | 4.2/5 | 4.0/5 | 4.5/5 | 4.0/5 | 4.4/5 |
| Capterra | 4.6/5 | 4.7/5 | 4.7/5 | 4.5/5 | 4.6/5 | 4.3/5 | 4.6/5 | 4.5/5 | N/A | N/A | 4.3/5 | 4.3/5 | 4.5/5 | 4.0/5 | 4.5/5 |
| Founded/Launched | 2011 | 2016 | 2006 | 2023 | 2000 | 2008 | 2019 | 2012 | 2011/2024 | 2015 | 2014 | 2001 | 2003 | 2016 | 2013 |
| Headquarters | Chicago, IL | Santa Barbara, CA | Toronto, Canada | Geneva, Switzerland | Fairfax, VA | Boston, MA | Panama/Lithuania | Paris, France / NYC | Cupertino, CA | Mountain View, CA | India | Czech Republic | Germany (original) | Tempe, AZ | Chennai, India |
| Users (Estimated) | 1M+ | 10M+ | 15M+ | 2M+ (Pass) | 6M+ | 30M+ | 15M+ | 15M+ | Millions | Millions | Unknown | 2M+ | Unknown | Unknown | 100K+ teams |
| Common Complaint #1 | Add-ons increase cost | UI less polished | No free plan | Newer product | UI dated | 2022 data breach | Free plan single device | Higher price point | Apple ecosystem only | Chrome-centric | No cloud backup option | No Linux support | Steep learning curve | Basic features | No desktop app |
| Common Complaint #2 | Repriced twice in 2026 (now $52.45/yr) | Premium doubled to $19.80 (Jan 2026) | Price up 33% (Mar 2026) | 2FA and sharing need Plus | Fewer advanced features | ICO £1.2M fine (2025) | Dual login process | Free plan discontinued | Limited cross-platform | Privacy concerns | Mobile limitations | Less modern UI | No cloud sync built-in | Upsells to Norton 360 | UI outdated |
| Common Complaint #3 | US jurisdiction | Limited customer support | No phone support | No live chat | Less known brand | Ongoing crypto theft linked | No phone support | No Linux app | Fewer advanced features | No secure notes | No public audits | Smaller brand awareness | UI not modern | No password sharing | Can't import Safari |
Password Managers I Recommend
- Keeper is the one I use, and I switched to it in 2021 after testing Bitwarden, 1Password and LastPass. It is not the cheapest option, but the built-in TOTP authenticator and the autofill reliability are why I stayed. When I log into a site with 2FA enabled, Keeper fills the password and the six-digit code, or the passkey if the site supports it. The browser extension scans 2FA QR codes directly from the desktop instead of making you reach for your phone. Keeper was among the first managers to implement passkey storage protected by biometrics or a PIN across platforms. One-Time Share lets you send a credential to someone who does not have a Keeper account, offline access works without a connection, and the company holds SOC 2 and ISO 27001 with zero security incidents in its history. EU data centres are now available, which matters if you want your vault inside GDPR jurisdiction rather than under US law. The downsides are real: BreachWatch dark web monitoring costs an extra $20 a year and should be included in paid plans, the code is closed source so you cannot audit it yourself, there is no email alias feature, and it is a US company even with EU storage. If you want one thing that works every day without you thinking about it, this is the one.

- Bitwarden changed my mind about free password managers. The free tier gives you unlimited passwords on unlimited devices, which nothing else matches. I imported 291 passwords from NordPass in about 40 seconds. The interface looks dated next to Keeper or 1Password, but it is fully functional, and the search stays fast with hundreds of entries. What matters more is that Bitwarden is completely open source, with regular third-party audits from Cure53, so the security claims are verifiable rather than asserted. Folders and collections handle the separation between personal and work accounts without paying extra, the password generator does passphrases as well as random strings, and self-hosting is available if you want full control. Premium is $10 a year, cheaper than every competitor. The problems are autofill bugs on Android and Chromium browsers, no dark web monitoring on the free plan, and US jurisdiction, though Bitwarden does maintain data processing agreements and lets you choose a server region. If you are not going to pay for a password manager, use this one and stop looking.

- 1Password is the most polished product in this list and the only reason I would recommend it over Bitwarden is Travel Mode. It temporarily removes sensitive vaults from your devices when you cross a border, so if customs asks you to unlock your phone, the work credentials are not there to find. That is genuinely useful and nobody else does it properly.
Watchtower monitors password health and breach exposure, autofill is reliable across platforms, and the family plan at $4.49 a month for five users is fair value. Past that, my enthusiasm runs out. The email alias feature only works with Fastmail, which makes it useless unless you are already a Fastmail customer, and Proton Pass gives you unlimited aliases with any email setup. The Secret Key requirement for new device logins is a hassle to store safely. There is no free plan at all, only a 14-day trial. The company is in Canada, a Five Eyes country. You are paying more than Bitwarden for polish rather than function, and for daily use I still prefer Keeper’s TOTP handling. - Proton Pass comes from the company behind ProtonMail and ProtonVPN, and Swiss jurisdiction gives it stronger legal protection than any US-based alternative. The standout feature is unlimited hide-my-email aliases. You generate a unique address for every signup, and if that site is breached or sells your data, you disable the alias and the spam stops. The Pass plus SimpleLogin lifetime deal at $199 never expires, which is good value if aliases are your priority. It is open source and audited, and a July 2025 Cure53 audit found only a low-severity issue where locked vaults kept passwords in memory for up to 30 minutes on Firefox, which Proton fixed immediately. The problem I hit in testing was site compatibility. Some websites refuse to work with Proton Pass at all, mainly financial and e-commerce sites, which are exactly the logins where you want autofill working. Keeper handles those same sites, and where neither manager can see the login fields, Keeper at least gives you a button to force the credentials in. Proton Pass has no fallback, and support requests about site compatibility have taken months. You also cannot create custom sections or extra fields. If privacy and aliases are your main concern, it is worth it. If not, the others are better daily drivers.
- RoboForm has been around since 1999 and it fills complex forms better than anything else I have tested apart from Keeper. Government forms, insurance applications, multi-field checkouts with separate shipping and billing addresses: it gets them right where 1Password, NordPass and Bitwarden all stumble. If you regularly deal with tax documents, medical paperwork, visa applications or job applications, that alone justifies it despite the dated interface. TOTP is built in, local-only storage is available if you do not want cloud sync, and the Security Center flags weak and reused passwords. The history is worth knowing. In 2014 RoboForm was encrypting and decrypting server-side, the client-side JavaScript had bias in its random number generator, the TLS configuration was vulnerable to POODLE, and SSL Labs rated them a C. That was bad. They rebuilt the architecture, removed server-side decryption, and the security model now matches modern competitors. I mention it because they responded to criticism rather than ignoring it, which is more than most vendors do. The remaining downsides are a clunky mobile app, limited sharing, no email aliases and no dark web monitoring on lower plans.
Password Managers I Do Not Recommend
- LastPass is the clearest avoid on this list. In 2022, attackers stole encrypted vault backups belonging to roughly 30 million users. Four years later people are still losing money. TRM Labs traced $35 million in stolen cryptocurrency through late 2025. The FBI linked a $150 million theft from Ripple co-founder Chris Larsen to the same breach. Security Alliance estimated total losses at $250 million as of May 2024, and individual incidents include $4.4 million in October 2023 and $5.36 million in December 2024. The UK Information Commissioner’s Office fined LastPass £1.2 million for inadequate security. TRM Labs traced funds to Russian exchanges including Cryptex, which the US Treasury sanctioned in 2024 for receiving $51.2 million in ransomware proceeds. LastPass still has not told customers that credentials stored in Secure Notes may be exposed. If you ever stored cryptocurrency seed phrases, private keys or sensitive credentials in LastPass before August 2022, move those funds now, then change every password, then leave.
- NordPass is heavily promoted by affiliates because Nord pays generous commissions, which is why you see it everywhere. After testing it I cannot recommend it. Load times are painfully slow on both the app and the extension, and I was stuck on loading screens for two to three minutes at a time. The autofill confuses itself with autogenerate on new password fields, tries to save random things like contact email fields on forms with no login at all, and rarely fires when you actually need it. More than once I accepted a generated password when creating an account and NordPass simply did not save it, which means a password reset and starting over. There is no built-in 2FA authenticator on the premium personal plan, which is difficult to defend in 2026 when Keeper, Bitwarden and RoboForm all include one. Reinstalling and switching networks changed nothing. The encryption is XChaCha20, the jurisdiction is Panama, and Cure53 audits it regularly, so the underlying security is not the issue. The product is. If you get it free with a paid Revolut plan, it is tolerable. Otherwise use Bitwarden for nothing or Keeper for a bit more.
- Dashlane discontinued its free plan in September 2025, so the entry price is now $4.99 a month. The family plan is $7.49 a month against 1Password’s $4.49 for the same five users, and that premium is hard to justify when the functionality is comparable. The interface is polished and autofill works reliably, though not as well as Keeper or RoboForm. The bundled VPN is the only genuinely unusual thing here, and it is redundant if you already pay for NordVPN, Proton VPN or anything else. Dark web monitoring needs a higher tier. There is no scenario where Dashlane is the right answer unless the bundled VPN is exactly what you were shopping for.
- Apple Passwords works well if every device you own is an Apple device, and falls apart the moment one is not. iCloud Keychain sync problems are well documented across Reddit and Apple’s own community forums: passwords that stop syncing between devices, entries reverting to older versions, the Windows iCloud app refusing authorisation for weeks. Users report changing their Apple ID password and re-authenticating every device just to get sync working again. There is no separate master password, so the vault is protected only by your device passcode or biometrics. The only export option is an unencrypted CSV file, and the process is buried, which is lock-in by design. macOS Sequoia made it worse by moving Keychain Access into a hidden system folder, removing it from the Dock and removing the ability to create new secure notes. There is no TOTP storage, no dark web monitoring, no secure sharing outside the ecosystem and no family sharing with non-Apple users.
- Google Password Manager is free because you are the product. Google already has your search history, email contents, location history, YouTube activity and Chrome browsing data. Adding bank logins and medical portal credentials to that profile is a risk I will not take. It is not zero-knowledge, which means Google can technically decrypt your data under legal request, and because it is closed source there is no way to verify the security claims independently. TechRepublic’s 2025 review noted that the encryption methods are not clearly documented for users. In July 2024 a bug locked 15 to 17 million Windows users out of their passwords for around 18 hours. There is no secure sharing, no built-in TOTP storage, no emergency access, and your Google account becomes a single point of failure for everything you own.
- Enpass sells itself on local storage and no forced subscription, which sounds good until you look at patch timing. Browser extensions are the main attack surface for password managers, and clickjacking, UI redressing and iframe manipulation have been documented for over a decade. At DEF CON 33 in August 2025, researcher Marek Tóth demonstrated DOM-based clickjacking against password manager extensions, where a single click on a malicious site can leak stored credentials, 2FA codes and card details by overlaying invisible elements over the autofill controls. You think you are dismissing a cookie banner. Tóth’s research tested 11 managers and found every one vulnerable to at least one vector, so this is not an Enpass-specific flaw. What separates them is response time. Keeper, NordPass, Proton Pass, RoboForm and Dashlane all patched before public disclosure. Enpass was listed as vulnerable at disclosure and was still patching afterwards, with protections inconsistent across platforms and browser versions according to Socket’s follow-up. That is the gap I care about in security software.
- Sticky Password offers local storage, optional cloud sync and a lifetime licence, which will appeal if you hate subscriptions. Everything else is stuck around 2015. The interface is dated, autofill is clunky, vault search is slow and the mobile apps lag. There is no built-in TOTP authenticator, no emergency access and no passkey support. Scroll the changelog looking for the last meaningful feature and you will be scrolling for a while. It has never had a major breach, but that is the minimum bar, not an achievement. Security software in maintenance mode is a liability.
- KeePass is a legitimate open-source manager with strong cryptography, and the software itself is not the problem. The distribution is. Attackers have bundled trojanised KeePass installers with malware and pushed them through unofficial download sites and search ads. If you download it from anywhere other than the official page and do not verify the file hash, you are gambling with your machine. For technical users who verify checksums and stick to official sources, KeePass is fine. For everyone else the risk is unnecessary when Bitwarden’s free tier does the same job with automatic updates and no verification step to forget.
- Norton Password Manager ships with Norton 360 and is also available free as a standalone product. It handles basic password storage acceptably and nothing more. There is no built-in TOTP authenticator, no secure sharing, no emergency access, and import options are severely limited even against free competitors. The encryption is AES-256 with zero-knowledge architecture, so the fundamentals are sound, but it feels like an afterthought to Norton’s main products. Bitwarden’s free tier is better in every way that matters.
- Zoho Vault is built for organisations inside the Zoho ecosystem, where it integrates well and has solid team management. For personal use it is wrong in every direction. The interface is designed for business administrators, with settings and tabs that mean nothing to an individual. Emergency access is only available on business plans. Autofill barely works beyond credentials, you cannot delete passwords shared with you, and Safari users cannot import at all. If your company already runs Zoho, fine. Otherwise there is no reason to be here.
Pricing and Renewal Comparison
Renewal pricing is where password managers behave worst, so check the second-year number before you buy, not the first.
| Manager | Free tier | First year | Renews at | Family plan | Trial or refund | Affiliate commission |
|---|---|---|---|---|---|---|
| Bitwarden | Unlimited passwords, unlimited devices | $19.80 a year, $1.65 a month | Same, no increase published | $47.88 a year for 6 users | 7-day trial | Not published |
| Keeper | Very limited | $52.45 a year, $4.37 a month | Same, no increase published | $112.23 a year for 5 users | 30-day refund | Restricted programme, low rate |
| 1Password | None | $35.88 a year, $2.99 a month | Standard rate $3.99 a month | $53.88 a year for 5 users | 14-day trial | Not published |
| Proton Pass | Yes, unlimited logins and devices | €35.88 a year, €2.99 a month | Standard rate €4.99 a month | €59.88 a year for 6 users | 30-day refund | Not published |
| RoboForm | Unlimited passwords, 1 device | €19.90 first year | €29.88, up 50 percent | €31.95 then €47.75, 5 users | 30-day refund | $2 per signup plus 25% |
| NordPass | Unlimited passwords, 1 device | €23.88 first year | €35.88, up 50 percent | €44.28 then €71.88, 6 users | 30-day refund | Not published |
| Enpass | Desktop only | $14.39 first year | $23.99, up 67 percent | $35.99 then $47.99, 6 users | 14-day trial | Not published |
| Dashlane | None since Sept 2025 | €47.16 a year, €3.93 a month | Not published | €71.40 a year for 10 users | 14-day trial | Up to 25% |
| LastPass | Yes, 1 device type | €34.80 a year, €2.90 a month | Not published | €46.80 a year for 6 users | 30-day trial | Not published |
| Sticky Password | Yes, no sync or sharing | €29.95 first year | €39.95 standard rate | Not offered | 30-day refund | Not published |
| Zoho Vault | Yes, personal use | €10.80 a year per user, business | Same, no increase published | Not offered | 15-day trial | Not published |
| Norton PM | Fully free | Free | Free | Bundled with Norton 360 | 60-day refund | Not published |
| KeePassXC | Fully free | Free | Free | Free | Not applicable | None, open source |
| Apple Passwords | Fully free | Free | Free | Free | Not applicable | None |
| Google PM | Fully free | Free | Free | Free | Not applicable | None |
Prices taken from each vendor's own pricing page in September 2026. Currency is shown as the vendor displays it to a European visitor, so some figures are USD and some EUR and they are not directly comparable. RoboForm, NordPass and Dashlane display prices excluding VAT. One-time options not shown in the table: Enpass lifetime $79.99, Enpass three-year $33.59, Sticky Password lifetime €79.95. Affiliate rates appear only where a vendor publishes one.
Security, Audits and Breach History
This is the table most roundups will not publish, because it makes several popular products look bad.
| Manager | Jurisdiction | Open source | Independent audits | Latest audit | Breach history | Clickjacking fix | Timing vs disclosure |
|---|---|---|---|---|---|---|---|
| Keeper | US, EU data centres available | No | SOC 2, ISO 27001 | 2024 | None | Fixed 17.2.0, 25 Jul 2025 | 15 days before |
| RoboForm | US | No | Secfault Security | Feb 2025 | Architecture issues 2014, rebuilt | Fixed 9.7.6, 25 Jul 2025 | 15 days before |
| Dashlane | France and US | Partial, mobile | SOC 2 Type II, ISO 27001 | 2024 | None | Fixed v6.2531.1, 1 Aug 2025 | 8 days before |
| NordPass | Panama and Lithuania | No | Cure53 | Feb 2025 | None | Fixed 5.13.24, 15 Feb 2024 | 18 months before |
| Proton Pass | Switzerland | Yes, full | SEC Consult, Cure53 | Jul 2025 | None | Fixed 1.31.6 | Before disclosure |
| Enpass | India | Partial | No public audit | Not applicable | None | Fixed 6.11.6, 13 Aug 2025 | 4 days after |
| Bitwarden | US, region choice available | Yes, full | Cure53, Insight Risk | 2024 | None | Fixed 2025.8.2, 31 Aug 2025 | 22 days after |
| Apple Passwords | US | No | Internal only | Not applicable | None | Fixed 3.1.30, 21 Oct 2025 | 73 days after |
| KeePassXC | Germany, community | Yes, full | Community reviewed | Not applicable | None | Fixed 1.9.11, 26 Nov 2025 | 109 days after |
| 1Password | Canada, Five Eyes | No | Cure53, SOC 2 | Feb 2025 | None | Still unpatched as of 14 Jan 2026 | Not fixed |
| LastPass | US, Five Eyes | No | Multiple | 2024 | 2022, roughly 30M vaults stolen | Still unpatched as of 14 Jan 2026 | Not fixed |
| Zoho Vault | India | No | Regular third-party | 2024 | None | Not tested | Not tested |
| Google PM | US, Five Eyes | No | Internal only | Not applicable | Jul 2024 lockout, 15 to 17M users | Not tested | Not tested |
| Norton PM | US, Five Eyes | No | Internal only | Not applicable | None | Not tested | Not tested |
| Sticky Password | Czech Republic | No | No public audit | Not applicable | None | Not tested | Not tested |
Clickjacking data from Marek Toth, DOM-based Extension Clickjacking, last updated 14 January 2026. All 11 managers he tested were vulnerable in default configuration. Vendors were notified in April 2025 and had more than 120 days before public disclosure at DEF CON 33 on 9 August 2025. 1Password and LastPass both classified the report as informative.
10 Tips for Choosing a Password Managers
- Check whether TOTP is included, and on which plan. Storing your 2FA codes in the same vault as your passwords is a trade-off, and I will come back to that, but if you want it, check the plan. NordPass does not include it on the premium personal plan. Bitwarden puts it behind the $10 premium tier. Keeper, 1Password and RoboForm include it.
- Calculate the three-year cost, not the first-year price. Password managers are less aggressive on renewals than antivirus vendors, but the pattern exists. Take the promotional price, add two renewals, and compare that number instead. Bitwarden at $10 a year flat wins this comparison against almost everything.
- Prefer open source, but check that it is actually audited. Open source means researchers can inspect the code. It does not mean anyone has. Bitwarden and Proton Pass both publish third-party audits, most recently from Cure53. If a vendor claims open source and cannot point you to an audit report with a firm name and a date, treat the claim as marketing.
- Check the breach history and how the company responded. LastPass is the obvious case, but the useful signal is not that a breach happened. It is what they did afterwards. LastPass has still not warned customers about credentials in Secure Notes, four years on. RoboForm had a genuinely bad architecture in 2014, rebuilt it, and said so publicly. Those two responses tell you different things about the companies.
- Check extension patch timing after a public disclosure. After Marek Tóth’s DEF CON 33 research, some vendors had fixes out before the talk and some were still working on it months later. Search for the product name plus the vulnerability and look at the dates. This is the single best proxy for how seriously a vendor takes security work that is not visible to customers.
- Test the import before you commit to anything. Every manager claims easy import. Try it inside the trial window with your real vault, then check that TOTP seeds, secure notes, custom fields and attachments all survived. Codes and notes are the usual casualties, and you will not notice until you need them.
- Test autofill on the sites you actually use, especially banks. This is where products separate. Simple logins work everywhere. Bank portals, government forms and multi-step checkouts do not. Proton Pass failed on financial sites in my testing while Keeper handled the same sites, and no feature list would have told you that.
- Check the export path before you go in. Assume you will leave one day. Apple’s only export is an unencrypted CSV and the option is buried. Zoho Vault will not let Safari users import at all. Before you move hundreds of credentials into a product, confirm you can get them out in a usable, encrypted form.
- Do not use your browser’s built-in manager for financial accounts. Google Password Manager is not zero-knowledge, which means Google can decrypt your vault under legal request. Apple Passwords has no separate master password. Both are fine for low-value logins and wrong for anything involving money or health data. If you use nothing else, at least separate those.
- A password manager does not fix a weak master password. Everything in the vault sits behind that one credential and the second factor protecting it. Use a long passphrase you have never used anywhere else, enable 2FA on the manager itself, and write the recovery kit down on paper stored somewhere physical. Zero-knowledge encryption means the vendor genuinely cannot help you if you lose it.
Still not sure which one?
Leave me a comment with what you need: how many devices, whether you want TOTP in the same vault, whether you need family sharing, whether you are in the EU and care about where the data sits, and your budget. I will point you to the right one.
Thanks,
Mefat

