A password manager is the rare purchase where the product's job is to hold the keys to everything else you own. Choose well and you get one strong, unique password per account without memorizing any of them. Choose poorly and you've built a single point of failure — or picked a tool so clunky your family or team quietly goes back to reusing Summer2024! everywhere.
The good news: this category is very judgeable. Password managers compete on a small number of verifiable properties, and once you know what they are, most of the marketing fog burns off.
The key takeaway up front: judge a password manager on five criteria, in this order — security model, account recovery, everyday usability (especially autofill), sharing and multi-device support, and total cost over time. Weight the first two heaviest: they're the ones you can't fix after the fact. This guide walks through each criterion; the scored side-by-side comparisons live on top-fully.com. (If you want the general method behind this kind of evaluation, start with our criteria-first comparison framework.)
First, settle the real question: do you need one?
If you currently reuse passwords, keep them in a notes app, or rely on "forgot password" as your login strategy, then yes — and the reason is mechanical, not moralizing. Credential-stuffing attacks work by taking passwords leaked from one breached site and trying them on every other site. Reuse is what makes one company's breach your breach everywhere. The only sustainable defense is a unique, random password per account, and no human maintains two hundred of those without software.
"But my browser already saves passwords." Built-in browser managers have genuinely improved, and one is far better than nothing. A dedicated manager earns its place when you need anything beyond the basics: cross-browser and cross-ecosystem sync, secure sharing with a partner or team, storage for more than passwords (cards, identities, secure notes, 2FA codes), breach monitoring, or an emergency-access plan. If none of those apply to you, a browser manager plus strong unique passwords is a legitimate budget answer — score it as a candidate rather than dismissing it.
Criterion 1: The security model (weight this heaviest)
Everything else on this list is recoverable from a bad choice. The security architecture isn't. Three properties to verify, in plain language:
Zero-knowledge encryption. "Zero-knowledge" means your vault is encrypted and decrypted on your device, using keys derived from your master password — so the provider stores only ciphertext it cannot read. The practical consequence: even if the company is breached, subpoenaed, or acquired, your actual passwords aren't exposed, only encrypted blobs. This is the non-negotiable baseline. If a provider can show you your password in plaintext through customer support, walk away.
Strong key derivation. Your master password is stretched into an encryption key by an algorithm designed to be slow — which makes guessing attacks expensive. Look for modern algorithms (Argon2 is current best practice; PBKDF2 with a high iteration count is acceptable) named openly in the provider's security documentation. A vendor that documents this precisely is signaling seriousness; one that says only "military-grade encryption" is signaling marketing.
Independent audits and disclosure history. You can't personally verify cryptography, so verify behavior instead: Does the provider publish third-party security audits? Do they run a bug-bounty program? When incidents happened — and in this industry, incidents happen — did they disclose quickly and specifically, or minimize and lawyer up? A documented, well-handled incident can be a better trust signal than a blank history and silence.
Open-source clients are a bonus on this criterion — independent researchers can inspect the code — but audits matter more than source visibility alone. Unaudited open source is a promise, not a proof.
Criterion 2: Account recovery (the criterion everyone forgets)
Here's the trade-off nobody advertises: true zero-knowledge means the provider cannot reset your master password, because they never had it. Forget it with no recovery plan, and your vault is cryptographically gone — no support ticket can bring it back.
So before you buy, answer: what happens when I forget the master password, lose my phone, or die? Compare candidates on which recovery paths they offer:
- Recovery codes or keys — a one-time code you print and store somewhere physical.
- Emergency access / trusted contacts — a designated person can request access after a waiting period you set.
- Biometric or device-based recovery — another enrolled device can re-authorize you.
- Family or team admin recovery — on multi-user plans, an admin can restore a member's access (check whether this is implemented in a way that preserves zero-knowledge; good implementations are, via key escrow you control).
There's a genuine tension here: every recovery path is also, technically, an attack path. The right answer isn't "maximum recovery" or "zero recovery" — it's a manager that lets you choose the trade-off deliberately. What you're screening out is the tool that offers no plan at all, and the household that discovers this at the worst possible moment.
Criterion 3: Everyday usability — autofill quality decides adoption
Security you don't use protects nothing. The single best predictor of whether a password manager sticks is the quality of its autofill: does it reliably detect login forms, fill them in one action, capture new credentials when you sign up somewhere, and update stored entries when you change a password?
Test this in a real trial, on the actual browsers and devices your household or team uses — the scripted-trial method from our comparison framework applies directly. Tasks worth scripting:
- Import your existing passwords (from a browser or another manager) and see what survives the trip.
- Sign up for a new account and confirm the manager offers to generate and save the password.
- Log in on mobile — iOS and Android autofill integration varies more than desktop.
- Change a password on an existing account and see whether the vault entry updates cleanly.
Also under usability: passkey support. Passkeys — the newer, phishing-resistant login standard — are gradually replacing passwords on major services, and a manager that can store and sync passkeys across your devices is better positioned for the next five years than one that treats them as an afterthought.
Criterion 4: Sharing, families, and teams
If more than one person is involved, sharing architecture becomes a first-class criterion:
- Granularity — can you share a single login, a folder/collection, or only the whole vault? Can you share without revealing the password itself (fill-only sharing)?
- Revocation — when someone leaves the family plan or the company, can you cleanly revoke access and see what they could have copied?
- Roles and audit — for SMBs: admin roles, per-group permissions, and an activity log are the difference between a consumer tool stretched thin and a team tool.
For a two-person household this criterion is a light weight. For a ten-person business it may deserve second place, right after the security model — offboarding an employee who had vault access is a scenario you want answered before it happens.
Criterion 5: Total cost over time — and the free-tier question
Password managers are cheap relative to what they protect, but pricing structures differ enough to matter. Score cost the way our framework prescribes: model year three, not month one.
- Free tiers vary enormously — some are genuinely usable (unlimited passwords, limited devices), others are trials in disguise (device caps, no sharing, no 2FA storage). A free tier funded by healthy paid plans is sustainable; check what the paid tier is before trusting the free one.
- Family plans are usually the best value per person — five or six members for less than twice the individual price. If you're choosing for a household, compare family-plan pricing directly, not individual pricing.
- Watch the renewal price, not the intro price, and check which features sit behind the higher tiers — 2FA code storage, advanced sharing, and emergency access are common upsells.
- Exit cost — confirm the manager exports to a standard format (CSV at minimum) before you import your life into it. Every serious contender does; the check takes two minutes and keeps every future decision reversible.
Putting it together: a worked weighting
Using the 1–5 weights from our framework, a reasonable default for an individual or family:
| Criterion | Weight | Why |
|---|---|---|
| Security model | 5 | Unfixable after the fact; the whole point of the product |
| Account recovery | 4 | The realistic worst case for most users is lockout, not hackers |
| Usability / autofill | 4 | Decides whether the tool actually gets used |
| Sharing & devices | 2–4 | Scale with how many people and platforms are involved |
| Cost over time | 2 | Real, but small stakes relative to the others |
An SMB would raise sharing/admin to 4–5 and keep the rest. Score three to five candidates against your weights, run a scripted trial on the top two, and decide.
FAQ
Is it safe to keep all my passwords in one place?
Safer than the alternative, for most people. A zero-knowledge vault protected by one strong master password and two-factor authentication concentrates your risk into a system built by security engineers — versus spreading it across reused passwords, which are the mechanism behind most real-world account takeovers. The honest caveat: the master password becomes critical. Make it long, unique, and backed by a recovery plan (Criterion 2).
What's the difference between zero-knowledge and regular encryption?
Regular ("at rest") encryption protects data on the provider's servers, but the provider holds keys and can decrypt it. Zero-knowledge means encryption and decryption happen on your device with keys derived from your master password — the provider only ever stores ciphertext it cannot read. For a password manager, zero-knowledge is the baseline you should require.
Should I use a free password manager or pay?
Score both against the same five criteria. Good free tiers and browser-built-in managers pass the security bar and beat sticky notes decisively. Paid plans typically earn their fee on Criteria 2–4: recovery options, cross-ecosystem autofill, 2FA storage, and family/team sharing. If several people or several platforms are involved, paid usually wins on the weighted total; for one person on one ecosystem, free can be the rational pick.
What happens to my passwords if the password manager company shuts down?
With a zero-knowledge design, your vault data is on your devices, not just their servers — a shutdown announcement typically comes with an export window, and local copies keep working in the interim. This is exactly why the exit-cost check matters at purchase time: confirm standard-format export exists before you commit, and a shutdown becomes an inconvenience rather than a crisis.
You know the criteria; now see them applied. We've scored the leading password managers on this exact rubric — security model, recovery, usability, sharing, and true cost — with the evidence behind every score. See our scored shortlist of password managers at top-fully.com and match it against your own weights.