How Password Manager Lab Ranks Password Managers
The ranking methodology weighs published audits, breach history, pricing transparency, platform coverage, and export freedom, with cited sources.
Password Manager Lab publishes reviews, head-to-head comparisons and setup guides for password managers and credential security tools. This page explains exactly how a ranking here is produced, so you can decide how much weight to give it.
The short version: every conclusion on this site is derived from primary documents — published third-party audit reports, vendor security design papers, official pricing pages, and documented breach disclosures. Every review lists its sources. Nothing here is based on private benchmarks, and no claim is made about hands-on trials that did not happen.
The five ranking inputs
1. Published third-party audits
The first question asked of any manager is whether an independent party has examined it and published the result. Three things are recorded: who audited it, what the scope was, and whether the report is publicly readable rather than summarised by the vendor’s marketing team.
This input separates the field sharply. Bitwarden publishes a continuous index of named engagements running from 2018 to the present, covering Cure53, IOActive, Mandiant, Fracture Labs, Unit 42 and a cryptography review by the Applied Cryptography Group at ETH Zurich — set out in the Bitwarden review. 1Password’s assurance rests on an Independent Security Evaluators penetration test, an Onica infrastructure audit, ISO 27001 and SOC 2 Type 2 certification, and annual pentest reports released through its Trust Center — covered in the 1Password review. KeePassXC holds an ANSSI CSPN certificate valid to November 2028 plus a 2023 independent code review, detailed in the KeePassXC review.
An audit is not proof of safety. It covers a snapshot of code at a point in time, and competent auditors miss things. What a published audit does prove is that the vendor was willing to be examined and to let you read the outcome. A vendor with no public audit record is not necessarily insecure, but it is asking for more trust than one that has been examined.
Open source is weighted separately, not as a substitute. Open code allows verification of the implementation; a published audit is verification that someone competent actually looked. The strongest position is both.
2. Documented breach and incident history
What has actually gone wrong, according to the vendor’s own disclosure or credible reporting — not rumour, and not competitor marketing. Three factors matter more than the raw existence of an incident:
- What was exposed. Encrypted vault blobs, metadata, or plaintext. These are not remotely equivalent, and conflating them is the most common error in password manager coverage.
- Disclosure quality. How long between detection and notification, and whether the initial statement held up as more became known.
- What changed afterwards. Key derivation defaults, architectural fixes, or nothing at all.
A vendor that disclosed a real incident clearly and fixed the underlying weakness scores better here than one with no public incidents and no transparency practice, because the second position is unfalsifiable.
3. Pricing transparency
Recorded from the vendor’s own published pricing page, with the retrieval date stated in the post. What gets checked:
- Whether the headline number is the standard rate or a first-year promotional rate that reverts on renewal
- Whether annual and monthly billing are both shown
- Whether the free tier is a functional product or a limited trial in disguise
- What a family plan actually costs per seat, and how many seats are included
- Whether tax is included in the displayed figure
Pricing changes. A figure quoted here is a figure as of the stated month, sourced to the page it came from. The Bitwarden vs 1Password comparison shows why that matters: 1Password’s March 2026 increase reset the entire value comparison in a single day.
4. Platform coverage
A support matrix is built for every reviewed manager: Windows, macOS, Linux, iOS, Android, each major browser extension, command-line tooling, and whether self-hosting is possible. Absences are stated rather than glossed over — no official mobile app, no Safari extension, no self-hosted server, no Linux desktop client. Coverage gaps decide more real purchases than feature checklists do, which is why Android coverage gets a roundup of its own.
5. Export freedom and lock-in
The most consistently under-reported dimension in this category. For every manager the questions are: can you get all your data out, in what format, from which platforms, and does anything block it?
The answers vary far more than you would expect. One product offers password-protected encrypted exports with no restrictions. Another produces plaintext-only files, cannot export from the browser extension, and disables export entirely for accounts that unlock through single sign-on. If you might ever want to leave, this section is more consequential than the pricing table.
What this site does not do
No paid placement. Coverage is not for sale. No outbound link on this site currently carries a referral or affiliate parameter, and nothing here earns a commission on any password manager it covers. If an affiliate relationship is ever added, the disclosure page will say so first and the article carrying the link will disclose it on the page. A product paying more would still not rank higher, because the published evidence sets the ranking.
No fabricated hands-on claims. This site does not claim laboratory testing, timed benchmarks, or long-term daily use it cannot evidence. Where a performance or reliability difference is described — autofill reliability on complex login forms, for example — it is attributed to documentation, vendor statements, or widely corroborated reporting, and framed as such.
No unsourced numbers. Prices, audit dates, iteration counts and seat limits are traceable to a linked primary source with a retrieval date.
No security theatre. Certifications are reported as what they are: process assurances. ISO 27001 says an information security management system exists and was audited. It says nothing about the strength of a key derivation function.
Where to start
- Choosing between the two obvious options: Bitwarden vs 1Password
- Deciding whether to pay at all: the best free password managers without artificial limits
- Moving off your browser’s built-in vault: browser passwords vs a dedicated manager
- Setting one up for a household: the family password manager comparison
- Getting the fundamentals right first: password security fundamentals and passkeys explained
- Hardening whichever you pick: using a YubiKey as your vault’s second factor
- Planning for the bad day: master password recovery options and what to do when a manager is breached
If you would rather answer a few questions than read the whole library, the password manager matcher ranks the field against your actual constraints. Unfamiliar terminology is defined in the glossary.
Who writes here
An editorial desk. Posts are published under the Password Manager Lab Editorial byline rather than individual names. It is an organization byline, not a pseudonym for a person.
Corrections are welcome and are the fastest way to improve this site. If a price has moved, an audit has been superseded, or a platform claim is out of date, write to editor@passmgrlab.com with the source and the post will be updated with a revised date.
See also
Related across the network
- Reconstructing an Incident Timeline From Primary Sources — aiincidents.org
Related
Are Browser Password Managers Safe to Use? Risk Guide
Browser password managers are safe enough for many people, but device access, sync security, extensions, and autofill settings affect their protection.
Is Bitwarden's Free Version Safe? What You Actually Give Up
Bitwarden's free tier uses the same AES-256 encryption and third-party audits as Premium. What $0 costs you, and the one KDF setting to check.
Best Password Manager for iPhone and Mac: 3 Real Options
1Password, Bitwarden and Apple Passwords compared for iPhone and Mac on Apple integration, security model, cross-platform reach, and price.