KeePassXC ranks #2 of 9 in our password managers testing. free, fully open, and the only one with no server at all — there is no vendor vault for anyone to steal..
89/100
structurally immune to the incident that defines this category, at the cost of doing your own syncing — a trade that is obviously right for some people and obviously wrong for others.
why people look for an alternative
−you supply and secure your own sync
−audit history found is a single dated certification
−mobile apps are third-party
−passkey support unconfirmed from current pages
stay with KeePassXC if no vendor server and no cloud vault to breach is the thing you care about most — nothing below beats it on that.
#4 in password managers · the best key architecture in the category, from the vendor that just made its audit reports harder to read.
84/100
verdictthe secret key design genuinely raises the floor on a weak master password — but a closed stack whose reports moved behind a request form in late 2025 is asking for more trust than it used to.
1Password vs KeePassXC
KeePassXC
1Password
price
free
$35.88/yr
free tier
yes
no
source
open: client, no server
closed: client + server
latest audit
anssi cspn, 2.7.9-era
2025, gated behind request
breach history
n/a — no server
none to vault data
free tier
entirely free
none — 14-day trial
individual/yr
$0
$35.88
switch forhouseholds and businesses who want the most polished product and will pay for it.
pros
+secret key design defeats offline brute force on a stolen vault
+srp authentication — password never transmitted
+soc 2 type 2 plus four iso certifications
+no breach of customer vault data in ~20 years
cons
−neither client nor server is open source
−recent audit reports gated behind trust center requests since nov 2025
−no free tier, only a 14-day trial
−losing both secret key and master password is unrecoverable
#9 in password managers · the only confirmed large-scale vault breach in this category, disclosed in unusual detail by the company that suffered it.
48/100
verdictranked last on the record rather than the technology: customer vault backups and unencrypted urls left the building in 2022, and no amount of subsequent hardening undoes that.
LastPass vs KeePassXC
KeePassXC
LastPass
price
free
unverified
free tier
yes
yes
source
open: client, no server
closed: client + server
latest audit
anssi cspn, 2.7.9-era
asserted, none named
breach history
n/a — no server
2022 vaults, 2015 hashes
free tier
entirely free
one device type
individual/yr
$0
not readable
switch forexisting users planning an export — and worth reading before choosing anything else, because the disclosure is genuinely instructive.
pros
+the most detailed, dated first-party breach disclosure here
+passkey creation and storage on paid tiers
+iso 27001, soc 2 type ii, soc 3 and bsi c5 certifications
cons
−2022 breach exfiltrated customer vault backups and metadata
−website urls in those vaults were never encrypted
−separate 2015 incident exposed hashes and reminders
−no auditor named and no report linked on its security page
every tool on this page went through the same test as KeePassXC — same tasks, same order, scored the same way. the comparison tables are the figures from that testing, not vendor spec sheets.