LastPass ranks #9 of 9 in our password managers testing. the only confirmed large-scale vault breach in this category, disclosed in unusual detail by the company that suffered it..
48/100
ranked last on the record rather than the technology: customer vault backups and unencrypted urls left the building in 2022, and no amount of subsequent hardening undoes that.
why people look for an alternative
−2022 breach exfiltrated customer vault backups and metadata
−website urls in those vaults were never encrypted
−separate 2015 incident exposed hashes and reminders
−no auditor named and no report linked on its security page
−free tier limited to one device type
stay with LastPass if the most detailed, dated first-party breach disclosure here is the thing you care about most — nothing below beats it on that.
#2 in password managers · free, fully open, and the only one with no server at all — there is no vendor vault for anyone to steal.
89/100
verdictstructurally immune to the incident that defines this category, at the cost of doing your own syncing — a trade that is obviously right for some people and obviously wrong for others.
KeePassXC vs LastPass
LastPass
KeePassXC
price
unverified
free
free tier
yes
yes
source
closed: client + server
open: client, no server
latest audit
asserted, none named
anssi cspn, 2.7.9-era
breach history
2022 vaults, 2015 hashes
n/a — no server
free tier
one device type
entirely free
individual/yr
not readable
$0
switch forpeople who would rather own the risk themselves than trust anyone's cloud with it.
pros
+no vendor server and no cloud vault to breach
+fully open source under gplv3
+completely free with no tiers
+anssi cspn certification on 2.7.9
cons
−you supply and secure your own sync
−audit history found is a single dated certification
#4 in password managers · the best key architecture in the category, from the vendor that just made its audit reports harder to read.
84/100
verdictthe secret key design genuinely raises the floor on a weak master password — but a closed stack whose reports moved behind a request form in late 2025 is asking for more trust than it used to.
1Password vs LastPass
LastPass
1Password
price
unverified
$35.88/yr
free tier
yes
no
source
closed: client + server
closed: client + server
latest audit
asserted, none named
2025, gated behind request
breach history
2022 vaults, 2015 hashes
none to vault data
free tier
one device type
none — 14-day trial
individual/yr
not readable
$35.88
switch forhouseholds and businesses who want the most polished product and will pay for it.
pros
+secret key design defeats offline brute force on a stolen vault
+srp authentication — password never transmitted
+soc 2 type 2 plus four iso certifications
+no breach of customer vault data in ~20 years
cons
−neither client nor server is open source
−recent audit reports gated behind trust center requests since nov 2025
−no free tier, only a 14-day trial
−losing both secret key and master password is unrecoverable
every tool on this page went through the same test as LastPass — same tasks, same order, scored the same way. the comparison tables are the figures from that testing, not vendor spec sheets.