Which Password Manager Should You Actually Trust?

Ten password managers ranked on the record that counts: published audits, breach history, vault architecture and how each vendor answered researchers.
which-password-manager-trust-featured

1Password is the one to trust with the things that would hurt most to lose, because its Secret Key means a stolen copy of your vault cannot be opened by guessing the master password. Proton Pass runs a close second and beats it on openness, with readable client code, two independent audits and a fix shipped within days when researchers broke the whole category. If you have decided you will never put a vault on anyone’s server, skip to KeePassXC and stop reading the cloud sections.


The shortlist, ranked by trust

  1. 1Password – Best overall – the Secret Key defeats the LastPass attack
  2. Proton Pass – Best open clients – two audits, fast under pressure
  3. Bitwarden – Best open cloud vault – readable code, self-hostable, a rough year
  4. KeePassXC – Best for zero trust – no server means no server to breach
  5. Keeper – Best certifications – audited to government standards, awkward history
  6. NordPass – Best modern crypto – strong cipher choices, closed doors
  7. Dashlane – Best disclosure – told users everything, after losing vaults
  8. RoboForm – Best on price – cheap and audited, with an old debt unpaid
  9. Aura – Least evidence – a vault inside a bundle, with nothing published
  10. LastPass – Avoid – the 2022 copies are still being cracked in 2026

The trust scoreboard

Nobody runs AV-Test for password managers. What exists instead is published audit reports, vendor advisories, academic papers, and one piece of research that tested every major browser extension at once. That is the evidence below.

ProductCodeIndependent auditVault incident on recordClickjacking fix
1PasswordClosedCure53, recurringNone (Okta tenant, 2023)Still listed unfixed Jan 2026
Proton PassClients openCure53 2023, Recurity Labs 2026None foundPatched
BitwardenOpenAnnual, every clientNone (npm CLI, 2026)Patched in 2025.8.0
KeePassXCOpenIndependent consultant, 2023No server to breachNot in the study
KeeperClosedSOC 2 Type 2, FedRAMPNone foundPatched
NordPassClosedCure53, repeatedNone foundPatched
DashlaneClosedSOC 2 Type II, ISO 27001Under 20 vaults taken, 2026Patched
RoboFormClosedSecfault Security 2025Generator flaw, fixed 2015Patched
AuraClosedNone publishedNone foundNot in the study
LastPassClosedNone published2022 vaults, 2026 support dataPartial only

Two events sit behind most of that table, and both happened recently enough that the older reviews you will find elsewhere do not account for them.

The first is DOM-based extension clickjacking, presented by researcher Marek Tóth at DEF CON 33. He tested eleven password manager extensions, which his analysis put at roughly 40 million active installations across the Chrome, Edge and Firefox stores, and found that a single click on a page an attacker controls could pull out logins, one-time codes, personal data, or card details. All eleven were vulnerable in some form. What separates them is what happened next: Dashlane, Keeper, NordPass, Proton Pass and RoboForm had shipped fixes within days, while Tóth’s own tracking page, updated in January 2026, still listed 1Password and LastPass extension builds as vulnerable.

The second is a paper from ETH Zurich and the Università della Svizzera italiana, presented at USENIX Security in Baltimore in August 2026. The researchers asked a question the marketing never does: what if the vendor’s own server turns hostile? Under that assumption they built 27 working attacks against Bitwarden, LastPass, Dashlane and 1Password, twelve against Bitwarden alone, ranging from tampering with one vault to compromising every vault in an organisation. Most of them recovered passwords. The vendors were given proof-of-concept exploits and 90 days before publication.


Best for: the specific fear that someone walks off with a copy of your vault.

At a glance: every major platform. No free tier, 14 days of trial. SOC 2 Type 2 and ISO 27001. Closed source. Individual and family plans, both repriced upward in 2026.

1Password large logo

The independent lab and audit record: 1Password publishes results from recurring third-party audits, with Cure53 penetration tests running from 2023 through 2025, and the transparency is better than most closed-source competitors manage. Its real defence is structural. The vault key is derived from your master password combined with a Secret Key generated on your device and never sent anywhere, which is exactly the attack that gutted LastPass users: a stolen backup is not crackable with a guessed master password alone. The ETH Zurich team reported achieving full compromise of vault confidentiality and integrity in their malicious-server model, and 1Password’s CISO publicly disputed how realistic those vectors are.

Pros:

  • The Secret Key makes a stolen vault copy useless on its own
  • Publishes recurring third-party audit results, unusual for closed source
  • SOC 2 Type 2 and ISO 27001 held and renewed
  • Travel Mode removes chosen vaults from a device before a border crossing
  • The most polished apps in the category

Cons:

  • Slowest response of the ten to the clickjacking research
  • Disputed the ETH Zurich findings rather than accepting them
  • No free tier at all, and prices rose in 2026
  • Closed source, so the audits are the only window in

The catch: it was the slowest here on the clickjacking research, classifying it as informative rather than a bug, and Tóth’s January 2026 table still listed the extension as vulnerable months after five competitors had shipped fixes. Disputing a paper is fair. Leaving an extension unpatched while doing it is the part that keeps this from being a clean win. It still finishes first because the Secret Key defeats the attack that emptied real people’s wallets, and no patch speed compensates for lacking that defence. Read the top two as a choice between the strongest architecture and the strongest behaviour. The head-to-head against Bitwarden, where that same response goes under a microscope, is covered in Bitwarden vs 1Password: Is Free Enough?.

The verdict: the strongest architecture on this page, first on what it protects you from and last on how it answers the people who test it.


Best for: anyone who wants code they can read, audits they can check, and a company outside American and EU reach.

At a glance: Windows, macOS, Linux, Android, iOS, plus browser extensions. Free tier with unlimited passwords. Client apps open source under GPLv3. Swiss company, launched in 2023.

1Password large logo

The independent lab and audit record: Cure53 audited the mobile apps, extensions and API in 2023 with full source access, reported a moderate number of findings mostly limited in severity, and called the overall state of security commendable. Every issue was resolved except one medium-severity item blocked by an Android platform limitation. Between January and April 2026 Recurity Labs, an ISO 27001 certified German consultancy with no financial ties to Proton, tested the browser extensions, the mobile and desktop apps and the command line tool, and Proton published the result. No remote exploits, no encryption bypasses, mostly low-impact findings, and one medium-severity issue in Android data removal that was fixed during retesting. Recurity rated the overall posture well above par. No breach of user vaults has been reported.

Pros:

  • Client apps published under GPLv3, so the encryption claims are checkable
  • Two independent audits on the public record, the most recent in 2026
  • Fixed the clickjacking flaw within days of disclosure
  • Encrypts metadata, not only the password field
  • Unlimited email aliases built in rather than sold as an add-on

Cons:

  • Server side is closed and cannot be self-hosted
  • Youngest product here, with three years of track record
  • Aliases tie you to Proton the longer you use them

The catch: the server side stays closed and there is no self-hosting, so the open code proves what your device does and not what Proton’s machines do. It is also the youngest serious product here, launched in 2023, and the aliases quietly tie you to Proton the longer you use them.

The verdict: two clean audits, readable clients, and the fastest reaction of the group when the category got broken, with only the closed server side and three years of history keeping it out of first.


Best for: people who want an open cloud vault, or their own server running the same apps.

At a glance: every major platform. A genuinely usable free tier with unlimited passwords and devices. Self-hostable. Premium is around ten dollars a year. ISO 27001 certified.

1Password large logo

The independent lab and audit record: Bitwarden completes annual source-code audits and penetration tests for each client, carried out by outside firms it names on its own compliance page. It also took the heaviest hit in the ETH Zurich work: twelve distinct attack types, including a malicious auto-enrolment where a hostile server could swap keys during organisation onboarding and take the vault without the user noticing. Bitwarden confirmed it addressed the vulnerabilities identified.

Pros:

  • Full client codebase published, and the server can be self-hosted
  • Annual source-code audits and penetration tests for every client
  • A free tier with unlimited passwords across unlimited devices
  • Argon2 available as the key derivation function
  • ISO 27001 certified

Cons:

  • Twelve attack types succeeded against it in the ETH Zurich study, the most of any product tested
  • Its own npm publishing pipeline was compromised in April 2026
  • Two separate security scares inside one year

The catch: 2026 has been rough. On 22 April a malicious build of the command line tool was published to npm and sat there for about 90 minutes by Bitwarden’s own account, harvesting cloud tokens, SSH keys and CI secrets from anyone who installed it, after attackers reached Bitwarden’s publishing pipeline through a compromised GitHub Action. Bitwarden revoked the access, deprecated the release, and found no evidence that vault data or production systems were touched. Your passwords were never the target. The delivery pipeline of a security company was, and that is the kind of access worth worrying about.

The verdict: openness and audit discipline that few match, with a year of scares keeping it out of the top two spots.


4. KeePassXC

Best for: anyone who has decided the safest server is the one that does not exist.

At a glance: Windows, macOS, Linux. Free, open source, no accounts and no subscription. Your vault is a single encrypted KDBX file you own. No official mobile app.

The independent lab and audit record: independent consultant Zaur Molotnikov audited KeePassXC in 2023 and concluded it gives sufficient cryptographic protection to what you store, provided you choose a strong passphrase and use the current file format. The project itself points out that an audit is not proof of safety and that flaws slip past good auditors. It sat out the malicious-server study for the simplest of reasons: there is no server to make hostile.

Pros:

  • No vendor server exists, so there is nothing to breach or turn hostile
  • Free and open source with no account and no subscription
  • Hardware key unlocking with YubiKey or OnlyKey
  • No telemetry of any kind
  • The vault file is yours, in a documented format

Cons:

  • Sync across devices is your problem to solve
  • An open vault does not sync live, so two devices editing at once conflict
  • No official mobile app, leaving phones to third-party software
  • Audit history is lighter than the funded competitors

The catch: everything the cloud products do for you becomes your job. Syncing the file across devices through Syncthing, Nextcloud or a cloud folder works, but an open vault does not sync live, so two devices editing at once produce conflicting copies. Mobile access depends on third-party apps the project does not control.

The verdict: unbeatable on attack surface, held back by a lighter audit history and sync you assemble yourself.


Best for: readers who want certifications checked by outside assessors rather than promises.

At a glance: every major platform. SOC 2 Type 2 held for over a decade, ISO 27001, 27017 and 27018, FIPS 140-3 validation, FedRAMP and StateRAMP authorisation. Closed source. Core plans are cheap, several security features are paid add-ons.

1Password large logo

The independent lab and audit record: the certification depth is the strongest here, and those are verified by independent assessors on a recurring basis rather than claimed once. There is no publicly disclosed breach of Keeper vault data, and it was among the group that patched the clickjacking within days of disclosure.

Pros:

  • The deepest certification set here, including FedRAMP and FIPS 140-3
  • SOC 2 Type 2 held and renewed for over a decade
  • Patched the clickjacking flaw within days
  • Record-level encryption with per-record keys
  • No publicly disclosed breach of vault data

Cons:

  • Sued a reporter and publication over a disclosed flaw in 2017, then dropped it
  • Dark web monitoring and reporting are separate paid add-ons
  • Closed source

The catch: in 2017, after a Google Project Zero researcher disclosed a browser extension flaw that Keeper patched within a day, the company sued the reporter and publication that covered it, then dropped the case. Patching in 24 hours and suing the person who told the world are two very different instincts from the same company, and security professionals said so loudly at the time. Add to that a pricing model where dark web monitoring and reporting are separate annual charges.

The verdict: the strongest paperwork on the page, discounted for a documented instinct to litigate rather than absorb criticism.


6. NordPass

Best for: people who want current cipher choices in an app that stays out of the way.

At a glance: every major platform. Free tier with unlimited passwords but one active device at a time. XChaCha20-Poly1305 with Argon2id. Closed source. SOC 2 Type 2 and ISO 27001.

1Password large logo

The independent lab and audit record: Cure53 has audited NordPass repeatedly since 2020, covering the desktop apps, mobile clients, browser extensions and the business edition, finding issues that were fixed and confirming the cryptographic design. No breach of user vaults has been reported. It was in the fast group on the clickjacking fixes.

Pros:

  • XChaCha20-Poly1305 with Argon2id, a more current pairing than most
  • Repeatedly audited by Cure53 since 2020 across every client
  • Fast clickjacking patch
  • No breach of user vaults on record
  • Clean, fast apps on every platform

Cons:

  • Closed source, so the audit summaries are all you get
  • Analytics run by default with no simple way to switch them off
  • The free tier logs you out of one device when you sign in on another
  • Published accounts place the company in three different countries

The catch: closed source means those Cure53 reports are the only window you have, and analytics run by default without a simple way to switch them off. The free tier logs you out of one device when you sign in on another, which stops being tolerable within a week. Published accounts also place the company in Lithuania, the Netherlands and Panama depending on where you read, which is an odd thing to have to guess about a privacy product.

The verdict: good cryptography and a clean incident record, limited by what you are allowed to see.


7. Dashlane

Best for: readers who judge a vendor by how it behaves on its worst day.

At a glance: browser-first design across every major platform. Limited free tier. AES-256 with Argon2d. SOC 2 Type II and ISO 27001. Closed source.

1Password large logo

The independent lab and audit record: annual SOC 2 Type II attestation and ISO 27001 certification, with third-party assessments running through 2025 and into 2026. Six attack types succeeded against it in the ETH Zurich malicious-server work. Then, starting 31 May 2026, an attacker ran a brute-force campaign against Dashlane’s device registration endpoints, guessing the six-digit tokens that gate 2FA, and succeeded on a small number of accounts: fewer than 20 personal-plan users had encrypted vaults downloaded before the automated controls contained it. Dashlane published a detailed advisory naming the endpoint, the method and the fixes, and closed the investigation on 4 June.

Pros:

  • Published a detailed advisory naming the endpoint, the method and the fix
  • Closed its investigation within days and reported the scope precisely
  • Argon2d key derivation
  • Annual SOC 2 Type II and ISO 27001 assessments
  • Browser-first design with monitoring included on paid tiers

Cons:

  • Encrypted vaults were downloaded from real accounts from 31 May 2026
  • Six attack types succeeded against it in the ETH Zurich study
  • 2FA tokens were the outer wall, and they were brute-forced
  • Closed source

The catch: encrypted vaults left the building. The encryption held and nobody has shown a decryption, but those files now sit with someone who has unlimited time to work on them, which is precisely the shape of the LastPass problem at a much smaller scale. Everything else Dashlane did afterwards was right.

The verdict: handled the incident about as well as anyone could, which does not undo the incident.


8. RoboForm

Best for: people who fill a lot of forms and want the cheapest paid option here.

At a glance: Windows, macOS, iOS, Android. Free tier available. Local-only storage is an option. AES-256. Closed source. Made by Siber Systems.

1Password large logo

The independent lab and audit record: Secfault Security audited RoboForm in February 2025 and reported that the vulnerabilities it found were patched quickly and effectively. It also fixed the clickjacking flaw within days. The problem lies further back. Versions before 7.9.14 generated passwords from a number generator tied to the date and time, which meant the output was predictable to anyone who knew roughly when a password was made. Joe Grand and a partner used exactly that in November 2023 to regenerate a 20-character password created on 15 May 2013 and open a wallet holding 43.6 bitcoin, worth around three million dollars at the time.

Pros:

  • Audited by Secfault Security in 2025, with findings patched quickly
  • Fixed the clickjacking flaw within days
  • Local-only vault storage is an option
  • Form filling remains the best in the category
  • The cheapest paid product here

Cons:

  • Passwords generated before mid-2015 are predictable and still in use
  • The company does not appear to have told customers to regenerate them
  • Never explained publicly how the generator was fixed
  • Closed source

The catch: Siber fixed the generator in June 2015 and does not appear to have told customers that passwords made before that date needed replacing, nor explained publicly how the fix works. One of the researchers said he would not fully trust it without knowing what changed. If you generated anything in RoboForm before mid-2015 and never rotated it, that password is still weak today.

The verdict: a solid modern product carrying an unpaid debt to its own users.


9. Aura

Best for: someone buying identity monitoring who treats the vault as a bonus.

At a glance: not a standalone product. The password manager sits inside an identity-theft protection subscription alongside antivirus, a VPN and credit monitoring. Closed source. No digital legacy, no external sharing.

1Password large logo

The independent lab and audit record: nothing published. No independent security audit of the vault component surfaced, and Aura was not among the eleven extensions in the clickjacking research either. That is not a clean record, it is an absent one, and the two look identical from outside only until something goes wrong. Every other product here has at least one report you can open and read.

Pros:

  • Bundles identity monitoring, antivirus and a VPN into one subscription
  • Encrypted vault with autofill, a generator and email aliases
  • Encrypted file storage for sensitive documents
  • Breach and dark web alerts included

Cons:

  • No independent security audit of the vault has ever been published
  • Not a standalone product, so the vault has no security page of its own
  • No digital legacy and no external sharing
  • Was not among the extensions tested in the clickjacking research

The catch: you cannot evaluate what a vendor does not publish. Aura sells a bundle, and the vault is a line item inside it rather than a product with its own security documentation, threat model, or audit history. For a shopping list that is fine. For the thing holding every credential you own it is not.

The verdict: a workable vault inside a bundle, judged on the bundle because there is nothing published about the vault itself.


10. LastPass

Best for: nobody starting fresh in 2026.

At a glance: every major platform, restricted free tier, AES-256, closed source. Still a competent product, which is not the question here.

1Password large logo

The independent lab and audit record: in 2022 an attacker took backups containing customer vault data, encrypted password fields alongside unencrypted ones such as stored website URLs. The consequences did not end there. The UK Information Commissioner’s Office issued a penalty in November 2025 over the failures behind it. A class action settlement of 24.45 million dollars took preliminary approval in February 2026, splitting into an 8.2 million dollar general fund and a separate 16.25 million dollar pool for people who lost cryptocurrency. Blockchain analysts at TRM Labs traced roughly 35 million dollars of theft to offline cracking of those vaults and warned of a long-tail risk to more than 25 million users, because any vault protected by a weak master password can still be broken years later. In June 2026 a separate incident exposed customer support case data when attackers compromised Klue, a third-party platform holding OAuth tokens into LastPass’s Salesforce environment; vaults were not affected, and disclosure came ten days after LastPass learned of it. On the clickjacking research, it patched card and personal data paths but not logins, passkeys or one-time codes.

Pros:

  • Mature apps on every platform, with long-standing browser integration
  • Password sharing and emergency access
  • Dark web monitoring on paid tiers

Cons:

  • Vault copies taken in 2022 are permanent and still being cracked
  • Thefts traced to those copies were still being recorded in 2025
  • A regulatory penalty and a class action settlement followed
  • Fixed only part of the clickjacking flaw, leaving logins and codes exposed
  • Customer support data exposed again in June 2026

The catch: those 2022 copies are permanent. Changing your master password today protects the account going forward and does nothing to the file an attacker already holds, which they can grind against for as long as they like. Three years on, the thefts are still being traced.

The verdict: a working product attached to the worst outcome in the category’s history, and the only one here with a live warning attached.


How we ranked them on trust

Softoto does not run a security lab, and no lab tests password managers the way AV-Test and AV-Comparatives test antivirus engines. There is no protection score to look up. Anyone presenting one has made it up.

So this ranking reads the people who do the work. Published audit reports from Cure53, Recurity Labs, Secfault Security and independent consultants. Certification attestations from outside assessors, which prove controls were checked rather than that code is flawless. The ETH Zurich and USI paper presented at USENIX Security this August. Marek Tóth’s DEF CON 33 research and the tracking page where he records which extensions have been fixed. Vendor advisories, which are the only source for what happened inside a company and are worth reading closely for what they leave out.

Three things none of that captures, which shaped the order above. Whether the vendor tells you quickly and in detail when something goes wrong, because Dashlane’s advisory is the model and LastPass’s ten-day gap is not. Whether the code can be read at all, since a closed product asks you to trust the auditor’s summary rather than the thing itself. And whether the company treats researchers as help or as a threat, which is why Keeper sits behind the open products rather than ahead of them.

One thing outranks all three, and it is why the slowest patcher here finished first. Architecture that removes an attack beats good behaviour after the attack lands. The 2022 LastPass copies are still being cracked because a master password was all that stood between the thief and the vault, and the Secret Key is the only design here that defeats that theft without taking your vault off the vendor’s servers entirely, which is KeePassXC’s answer to the same problem. Response speed decides the order among products whose architecture is comparable, which is where it separates Proton Pass from Bitwarden. It does not outweigh a structural defence against the thing that actually happened to millions of people.

The order above is Softoto’s editorial judgment on those grounds. It is not a measurement, it is not a test result, and it is not anyone’s lab output. Ours to defend, and easier to defend when the evidence behind it is listed openly above.


Which one is right for your situation

  • You store crypto recovery phrases or bank credentials: 1Password, for the Secret Key.
  • You want open code, a published audit trail and fast fixes: Proton Pass.
  • You are moving a family off reused passwords and cannot pay: Bitwarden’s free tier.
  • You want to run the server yourself: Bitwarden, self-hosted.
  • You refuse to put a vault online at all: KeePassXC, with Syncthing if you need two machines.
  • Your employer requires FedRAMP or SOC 2 evidence: Keeper.
  • You are on LastPass today: any of the top four, but rotate your old credentials first and choose second.

Is LastPass safe to use in 2026?

The current product encrypts vaults the way its competitors do, and the 2026 support-data incident did not touch vaults. The problem is historical and permanent: copies taken in 2022 are in circulation, weak master passwords are still being cracked from them, and money is still being stolen years later. If your vault existed before December 2022, the risk is not about what LastPass does now.


Does open source make a password manager safer?

It makes claims checkable, which is different. Bitwarden and Proton Pass publish client code, and independent researchers can confirm the encryption happens where the vendor says it does. It does not prevent bugs, and it did not stop Bitwarden taking the most hits in the ETH Zurich paper. Read it as a transparency guarantee, not a security one.


What does an independent security audit actually prove?

That a named firm looked at a defined scope on a specific date and reported what it found. It does not certify the product is safe, a point KeePassXC makes about its own audit. What matters is the pattern: recent audits, a published scope, and evidence the findings were fixed. A vendor with no audit at all, which describes Aura’s vault here, gives you nothing to check.


Should you turn off autofill in your browser extension?

Not entirely, but tighten it. Tóth’s recommendation for anyone on a Chromium browser is to set the extension’s site access to run on click, which stops it acting on pages until you ask. It takes about ten seconds in extension settings and removes the silent autofill that the whole clickjacking technique depends on.

Here is where this goes. The two extensions still listed as unfixed will be patched, because the research is public and the pressure is one-directional, and the scoreboard above will change when they are. The harder prediction is that the malicious-server threat model becomes the standard the next round of audits is written against, which means the vendors who answered the ETH Zurich work by disputing its realism will be answering it again with code. Expect the gap between the top four to close on architecture and widen on conduct. Trust records move, and this one gets rewritten when they do.

Share:
Founder & Editor-in-Chief

Nasreddine is the founder of Softoto, a software download library and blog covering Windows, Mac, and mobile software. He spends his days verifying installers, tracking version histories, and separating real developer downloads from the fakes that outrank them. He tests what he can install himself, sources the rest from developer changelogs and advisories, and always says which one it was. Questions or corrections: contact@softoto.com

Discussion

(0)
{{ reviewsTotal }}{{ options.labels.singularReviewCountLabel }}
{{ reviewsTotal }}{{ options.labels.pluralReviewCountLabel }}
{{ options.labels.noReviewsLabel }}
{{ options.labels.newReviewButton }}
{{ userData.canReview.message }}