Password managers live or die on trust, and LastPass has spent years testing how much of it people will extend. This password manager ships as apps on Windows, macOS, Android, and iOS, reaching Linux through the browser extension alone, and its free tier still stores an unlimited number of logins. Two questions decide whether you should download it: whether its security history still sits right with you, and whether the free plan covers the devices you actually use.
LastPass free storage is unlimited, but only on one kind of device
Most paid managers cap their free tier by item count. LastPass does not. The free plan holds as many logins, cards, and notes as you want, runs the password generator, and includes dark web alerts several rivals hold back for paying customers. The ceiling sits elsewhere. A free account works on one device type, computers or mobile, never both. So the answer to whether LastPass is free is yes, with a wall you meet the first time you open the vault on your phone after building it on a laptop.
Recent releases have gone mostly into the standalone desktop app, which now carries a floating fill companion able to drop credentials into ordinary Windows and Mac programs rather than web pages alone. That closes a gap the browser extension never covered.
Do I need the LastPass desktop app or just the browser extension?
For most people the extension is enough, and the other pieces exist for what it cannot reach. The three surfaces do not behave identically, which matters more here than with rivals shipping one app everywhere.
The browser extensions and the web vault
Extensions cover Chrome, Edge, Firefox, Opera, and Safari, and they carry the everyday work: capturing new logins, filling saved ones, generating passwords, and flagging weak or reused entries. The web vault handles the rest, including sharing, import, export, and the security dashboard.
The standalone desktop app
The desktop client on Windows and macOS gives the same vault outside the browser, and its fill companion is the reason to bother with it. That companion sits as a small floating widget and fills credentials into desktop programs and remote sessions. On macOS it does nothing until you grant Accessibility permission, which the app requests on first run and which people routinely dismiss, then wonder why nothing fills.
The mobile apps and system autofill
Android and iOS both get full apps with biometric unlock, and both hook into the operating system’s own autofill so logins appear inside other apps, not only the mobile browser. Android has needed a permission reset more than once after platform autofill changes, making the mobile app the piece most likely to want attention after a system update.
The free plan ceiling and what a paid LastPass tier adds
The device-type choice is the decision that catches people. Free accounts pick Computers or Mobile as their active type, and that choice is not a switch you keep flipping: LastPass allows a small, fixed number of changes and then locks the account to whichever side it landed on. Nothing warns you about the counter while you are importing two hundred logins from a browser, so plenty of people discover the lock after the vault is already full.
Paying lifts that ceiling and adds one-to-many sharing, more encrypted file storage, hardware key support for multifactor login, and emergency access for a trusted contact. Family plans give each member a separate vault. None of it is unusual for the category, and the upgrade exists mostly to sell you the second device type.
The breach record and what it changes for your master password
This is the part that decides the download for most readers, so take it straight. LastPass has disclosed multiple security incidents, and the worst ended with attackers holding encrypted vault backups plus unencrypted data such as names, billing addresses, and the website addresses stored in those vaults. A separate incident at an outside supplier later exposed customer contact details and support records, though vaults were untouched that time. LastPass US LP now runs independently of its former parent company, has rebuilt its security organisation, and raised its key-derivation strength.
What that means practically is narrower than the headlines suggest. Encrypted vaults are only as strong as the master password protecting them, so a short or reused one is the real exposure. LastPass is still a capable password manager and vastly better than reusing passwords across sites, but it earns a place only if your master password is long, unique, and never typed anywhere else. The stolen site addresses also mean phishing aimed at you can look convincingly specific.
LastPass compared with 1Password, Proton Pass, and Bitwarden
The three realistic alternatives each beat LastPass at something different. 1Password has no free plan at all, but its Secret Key means a stolen vault cannot be attacked with the master password alone, and its filling handles awkward multi-step logins better than the rest. Proton Pass comes from a Swiss company, is open source, and syncs its free tier across every device you own, the exact thing LastPass charges for. Bitwarden is open source too, has a free tier with no device limit, and is the only one here you can host on your own server.
LastPass answers with a generous single-device free tier, desktop program filling, and an interface non-technical family members pick up quickly. Choose it if you use one class of device and want something familiar. Choose Bitwarden if price and auditability matter, Proton Pass for a strong free tier from a privacy-focused company, and 1Password if you will pay for the smoothest daily experience.
| Feature | LastPass | 1Password | Proton Pass | Bitwarden |
|---|---|---|---|---|
| Free plan | Yes | None, trial only | Yes | Yes |
| Free plan device coverage | One device type | Not applicable | All devices | All devices |
| Free password storage | Unlimited | Not applicable | Unlimited | Unlimited |
| Biggest catch on the free plan | Computers or mobile, not both | No free tier exists | Limited vaults and aliases | No built-in code generator |
| Encryption | AES-256 | AES-256 | AES-256 | AES-256 |
| Key derivation | PBKDF2 | PBKDF2 plus a Secret Key | Argon2 | PBKDF2 or optional Argon2id |
| Second secret besides the master password | No | Yes, the Secret Key | No | No |
| App code open to inspection | No | No | Yes | Yes |
| Self-hosting your own vault | No | No | No | Yes |
| Company base | United States | Canada | Switzerland | United States |
| Known incident exposing customer data | Yes, more than once | No vault breach reported | No vault breach reported | No vault breach reported |
| Desktop app | Windows, Mac | Windows, Mac, Linux | Windows, Mac, Linux | Windows, Mac, Linux |
| Native Linux app | No | Yes | Yes | Yes |
| Browser extensions | Chrome, Edge, Firefox, Opera, Safari | Chrome, Edge, Firefox, Safari, Brave | Chrome, Edge, Firefox, Safari, Brave | Chrome, Edge, Firefox, Safari, Brave |
| Passkey storage | Yes | Yes | Yes | Yes |
| Dark web monitoring | All plans | Included | Paid plans | Breach check free, reports paid |
| Emergency access for a trusted contact | Paid plans | No dedicated feature | No | Paid plans |
| Built-in email aliases | No | Through an integration | Yes | Through an integration |
| Import and export your vault | Yes | Yes | Yes | Yes |
| If the master password is lost | Company cannot recover it | Cannot recover without the Secret Key | Company cannot recover it | Company cannot recover it |
| Strongest fit | One device type, familiar interface | Smoothest daily filling | Free tier and privacy | Price, auditing, self-hosting |
Setting up LastPass without stranding your existing passwords
Order matters here, because two of these steps are hard to undo once the vault is populated.
Run the security dashboard afterwards; it usually surfaces a dozen reused passwords you had forgotten about.
The kind of user LastPass still suits
If you keep your logins on one class of device, want a free vault with no item limit, and will maintain a master password you never reuse, LastPass is worth the download and a large upgrade over passwords saved in a browser. Anyone who needs phone and laptop covered without paying, works mainly on Linux, or cannot get past the security history should look at Bitwarden or Proton Pass instead. LastPass still works well; it just asks you to hold up your end.