Password Manager Lab
site

What Password Manager Lab is and how we test

Our methodology for reviewing and comparing password managers: what we test, what we don't accept, and how to read our coverage.

By PML Editorial · · 7 min read

Password Manager Lab publishes independent reviews, head-to-head comparisons, and setup guides for password managers and credential security tools.

What we cover

How we evaluate

Every manager review scores the same seven dimensions:

  1. Encryption model — where keys are derived, whether zero-knowledge is actually zero-knowledge, and what the audit record looks like
  2. Cross-platform reach — iOS, Android, Windows, macOS, Linux, browser extensions
  3. Auto-fill reliability — tested on a fixed set of login pages including financial sites, government portals, and poorly-built forms
  4. Sharing and recovery — emergency access, family plan usability, what happens when you lose your device
  5. 2FA integration — built-in TOTP, hardware key support, whether the vault itself requires MFA at login
  6. Breach monitoring — Pwned Passwords / Have I Been Pwned integration, scope, accuracy
  7. Price and business model — what the free tier actually includes, whether the pricing is stable, and what we know about the company’s ownership

What we don’t do

We don’t accept payment for coverage. Affiliate links exist on this site (disclosed on every post that uses them), but they don’t determine what we write or how we rate. A manager that pays more in commissions does not get a higher score.

We don’t review products we can’t install and test ourselves. That excludes enterprise-only tools with no trial access. If a review has restrictions, they’re stated.

We don’t pretend audit reports are a substitute for independent testing. We read them. We also test.

Who writes here

Pseudonymous editorial team. Tips and corrections welcome via editor@passmgrlab.com.

#meta #methodology

Related

Comments