Independent reviews

The best password managers we’ve tested so far

We test the details that decide whether a password manager stays useful: its free-plan limits, browser support, and everyday vault experience.

Every review checks the encryption claims and what happens to your credentials if you stop paying or decide to leave.

The password managers we've tested

Deeper dive: what each one is actually like

RoboForm Review 2026: Free Plan, Price & Every Browser

RoboForm

RoboForm Review 2026: Free Plan, Price & Every Browser

RoboForm has been filling in web forms since 1999, longer than any rival on the market, and still does it better than almost anything newer — Premium runs under a dollar a month, and the free plan is genuinely unlimited on one device.

Aug 27, 2026 21 min read

NordPass Review 2026: Price, Free Plan, Extension & Business

NordPass

NordPass Review 2026: Price, Free Plan, Extension & Business

NordPass encrypts with the same cipher Google and Cloudflare use and has passed repeated third-party audits — the free plan is genuinely unlimited but restricted to one device at a time, the detail most likely to decide which plan you actually need.

Aug 23, 2026 22 min read

Side by side

Every password manager we have reviewed, with publication date and review length
Password manager Review published Length Link
RoboForm Aug 27, 2026 21 min read Read
NordPass Aug 23, 2026 22 min read Read

No scores or award badges here on purpose — we don't publish a number we can't show the working for. Each review lays out what we found and what it cost.

Buying guide: choosing a password manager

Why a manager beats the system you have now

Almost everyone reuses passwords, because remembering unique ones is not something people can do at the scale modern life demands. Reuse is what turns a single breach at a company you barely remember signing up to into a break-in on your email, and from there on everything attached to it.

A password manager fixes that by making the passwords something you never have to know. Each account gets a long random string, the manager fills it in, and the only thing you memorise is one strong passphrase. The security benefit is not subtle — it removes the single most exploited weakness in ordinary people's accounts.

The catch is that it concentrates risk. One vault now holds everything, which is why how that vault is encrypted, and what happens if you lose access to it, are the questions worth being fussy about.

Zero-knowledge is the claim that matters

The important architectural property is that encryption and decryption happen on your device, with a key derived from your master password that the provider never receives. This is usually described as zero-knowledge or end-to-end encryption, and it means a breach of the provider's servers exposes ciphertext rather than your passwords.

It also means nobody can recover your vault if you forget the master password. That is not a flaw — it is the same property doing its job — but it does mean the recovery options a provider offers deserve a close look, because a recovery mechanism that works without your master password implies someone else can reach your data.

As with VPN audits, look for an independent security assessment with a published report, and check what it actually covered. A penetration test of a web front end is not the same as a review of the cryptographic design.

Free plans are where the real limits hide

Most managers offer a free tier, and the restriction is rarely the number of passwords. It is far more often the number of devices: unlimited passwords, but usable on one device at a time, which is close to useless when the point is filling passwords on both your laptop and your phone.

Other common limits are the absence of secure sharing, no emergency access for a family member, restricted two-factor options, and no encrypted file storage. None of those are unreasonable things to charge for. They are just worth knowing before you migrate a hundred accounts into a product on the assumption the free plan is enough.

Check that you can get your data back out

Before committing, confirm the manager offers a full export in a standard format such as CSV or an unencrypted JSON file you can import elsewhere. This matters for two reasons: it protects you if the company is acquired, changes pricing, or suffers a breach you are not comfortable with, and it means a lapsed subscription cannot hold your credentials hostage.

It is also worth checking what a downgrade actually does. Some providers put an expired vault into read-only mode, which is inconvenient but recoverable. Being locked out entirely would not be, so it is the sort of thing to establish while you are still choosing rather than at the point it matters.

Whichever product you land on, turn on two-factor authentication for the manager itself and write the recovery codes on paper. The vault is now the single most valuable account you own, and it should be the best defended.

Before you pay, check these

  • Zero-knowledge encryption. Keys derived on your device; the provider never holds your master password.
  • An independent security audit. Published in full, recent, and covering the cryptography rather than just the website.
  • Device limits on the free plan. Unlimited passwords on one device is a common and easily missed restriction.
  • A working export. Confirm you can take a full copy of the vault out in a standard format.
  • Two-factor on the vault itself. Plus recovery codes stored somewhere offline.
  • Browsers and phones you actually use. Extension quality varies far more between browsers than the feature grid suggests.

How we test

We buy the subscriptions at full price rather than accepting review copies, so everything below is based on actually using the product — including the parts that only show up after you've paid, like the renewal price and how hard the software is to cancel or remove.

PrivacyTestLab does earn money from a small number of affiliate partnerships, and those links are marked. What that money does not do is change a verdict: written recommendations go through the same evaluation regardless of whether an affiliate relationship exists, and no business pays for placement on this page. The full breakdown of how the site earns is on the transparency page.

Common questions

Is it safe to keep all my passwords in one place?

It is safer than the alternative most people are living with, which is reusing a handful of passwords everywhere. With zero-knowledge encryption the provider stores only ciphertext, so a breach of their servers does not expose your credentials. The concentration of risk is real, which is why the master password and two-factor authentication matter so much.

What happens if I forget my master password?

With a properly designed manager, the vault is unrecoverable. That is the direct consequence of the provider not holding your key. Some offer recovery through a trusted contact or a recovery code generated in advance, and setting that up on day one is worth the five minutes.

Is the password manager built into my browser good enough?

Browser managers have improved considerably and are far better than reusing passwords. They tie you to one browser ecosystem, generally offer weaker sharing and auditing features, and are unlocked whenever your browser profile is. For many people they are a reasonable middle ground; a dedicated manager is more portable and more capable.

Do I still need one if I use passkeys?

Passkeys remove the password for a growing number of services, but only for those services. You will be maintaining ordinary passwords for years yet, and most managers now store passkeys alongside them, so a manager remains the practical place to keep both.

Can I move my passwords between managers?

Usually yes — most support CSV export and import. Check that the manager you are considering offers a full export before you migrate to it, and delete the exported file afterwards, since it is a plain-text copy of every credential you own.

Bought, tested, and written independently

Every product on this page was paid for out of pocket and used before it was written about. Nothing here is a press release, and no business can buy a place on the list or a change to what we found.

  • Subscriptions bought at full price
  • No paid placements
  • Negative findings published too

Browse other categories