2026 Password Manager Tier List: Does Yours Stack Up?

We compared the top password managers (and the ones not quite there yet) to find out how they stack up. Let us know where your favorite choice fell, or if we missed anything in the comments!

3 Likes

i’m not getting how Keypass gets S-tier when you have to spend 5 minutes explaining all of the caveats it has (you have to do your own backups, there’s no cloud sync unless you set up your own deal, for advanced users, etc)… ? Simply being able to air-gap it doesn’t sound like something that should bump it to the top – you can air-gap most of these as long as you don’t want to sync them.

1 Like

I wouldn’t even whisper “LastPass” to anyone either, but I don’t think you blamed the company right for trying to sweep it under the rug. If you look at how these companies disclosed details about severe security breaches, you can see that they all generally follow the same playbook of minimizing the information/attention while appearing to be open about it at the same time. You can see the same thing with the “PasswordState” password manager as well. These companies serve their investors first and need to follow advice from their legal, sales, and marketing departments.

It’s really open-source software that would be able to hide less when such things occur, because parts of its development process can be readily inspected. That is one of the things that makes such companies different in these situations (okay, there are others, like independent auditing, etc.). The other type of company is basically one that has never experienced these events: they are either really good at security, or bad things just haven’t happened to them YET.

P.S. Look at Bitwarden: they had already mitigated the breach, but somebody else published about it first. Did Bitwarden have a postmortem? They are all trying to minimize attention to such events.

I use KeePass specifically because it’s offline. I haven’t switched even though I’ve tried Proton Pass and Bitwarden. But the caveats of using an offline password manager isn’t a bad thing. It’s just information that has to be communicated.

6 Likes

Thank you for this comparison. It is appreciated.

I do have some notes, though :slight_smile: :

Are these comparisons meant to focus on usability / feature completeness? If so, it might be worth a mention. E.g.: I would never trust a commercial company offering closed source software with my passwords (if only because greed trumps security), and for that reason alone would never consider 1Password to be a viable option.

It might have been worthwhile to mention that VaultWarden supports many features that are officially only covered by paid BitWarden tiers, so that publicly hosted VaultWarden instances offer a way to get more out of free BitWarden tiers (or some may like to self host).

Last but not least: have you considered adding AliasVault to the comparison?

Cheers.

I don’t use 1Password myself, but how is 1Password more greedy than, say, Bitwarden?

For me every non open-source password manager is honestly E / F Tier (aka unusable).

Also I think a password manager should be by default offline and you can just sync / transfer the database yourself. In my case I just only update / add passwords on my pc and then copy the database to my other devices regularly, no cloud at all. And I don’t feel any discomfort in doing this …

My current setup is Filen + KeePassDX. Personally it works well for me, and being able to decrypt the password database on my phone directly from Filen mitigates any worries I had about syncing the database. I was originally manually uploading a new database file to Filen every time I added new passwords to KeePassDX, but that proved cumbersome and obnoxious.

I know some users have had file corruption issues with Filen, but it hasn’t happened to me yet; fingers crossed it never does.

1 Like

That’s a fair question.

I was trying to say that commercial companies, when choosing between money and (for example) security (and everything it takes to get it right) have proven to take shorcuts leading to security incidents. There have been plenty of examples of this (LastPass for instance) and it seems to be almost inevitable, especially when stakeholders are involved.

Don’t get me wrong, I’m aware of (and concerned with) recent turns by BitWarden, which seems to be heading in the same direction. However, since KeePassXC no longer feels like an option for me, I’ll have to trust some company, and therefore I’d choose the one offering open source solutions.

I will keep a close eye on BitWarden, though, and may be switching over to AliasVault at some point.

Haha, jumped to roughly three quarters, landed on KeepassXC > S tier > ok I’m good.

Using LastPass as an example is a bit disingenuous because it implies that both companies have the same approach to security due to being closed source. 1Password has a blog about what would happen in an event of a breach (which hasn’t happened yet). LastPass don’t encrypt crucial metadata like 1Password does, and the attacker would need your secret key as well as your master password to decrypt your 1Password vault. IF they can obtain both, it would most likely be your fault rather than 1Password.

But your response doesn’t really explain how 1Password is greedy. In fact, it sounds like Bitwarden is also greedy, even if less so than 1Password. We could make the same argument about Proton vs. Google. Proton is less greedy because they don’t sell your data, but they’re still greedy because they’re more focused on building their ecosystem than working on requested features for their existing products.

It seems like “greed” is used too broadly here and it’s more about trusting open source rather than closed source.

We can disagree on what it implies, and the word “greed” might indeed be too broad a qualification. My main take on the myriad of issues plaguing LastPass is that shortcuts are inevitably being taken (when push comes to shove) if companies are weighing profit against the quality of their products / services, as long as their source code cannot be scrutinized. It may sound unfair, but I tend to believe that is the case with most software companies. I’m not trying to say they are “bad” people, but capiitalism has a tendency to steer people in that direction.

1 Like

Would have to disagree to use that catch all phrase …

I specifically chose one that was superior for enterprise and SMB’S and also offered a product to the private consumer. Their history of business and capturing and moving and expanding into other geographic markets was a plain indicator to me that they were a safe bet. Previous employees also expanded on their security record …

A neighbour of mine had been using the product for 20 years, both in enterprise and personally. There would be no reason to jeopardize a successful business by being lax or inattentive.

LastPass does however expose the worst of the worse.

Fair enough.

Then again, I used to trust a cloud storage company based on similar arguments, until they decided change course and started to focus on space and robotics. :sweat_smile: