We would like to count page views and clicks with Google Analytics, which sets cookies in your
browser. It is how we learn which pages are worth writing. Nothing loads until you choose, and
declining costs you nothing on this site. What we collect.
LastPass alternatives, and how to move a vault without losing it
Leaving LastPass is not like changing VPN. The vault holds every account you have, the export is a plaintext file for as long as it exists on your disk, and anything the 2022 breach captured is still out there being attacked offline. This page covers where to go and, just as importantly, the order to do it in.
LastPass scores 50 on this page's weighting, owned by GoTo (LogMeIn). Every pick below beats it on the things this page weighs.
Why people replace LastPass
An attacker took customer vault backups in 2022
Encrypted password fields were still protected by each user's master password, but site URLs were stored unencrypted, so whoever holds those files can see every service each victim used and can keep guessing master passwords offline for as long as they like. Time does not help you here; it helps them.
The architecture has no published independent audit
There is no public independent audit of the current design to point at, in a category where Bitwarden, 1Password and Proton Pass all publish Cure53 reports. For a product that asks you to trust encryption you cannot inspect, that absence is the whole argument.
Ownership changed hands through private equity
LastPass came under GoTo, formerly LogMeIn, which was taken private in 2020 by Francisco Partners and Evergreen Coast Capital for $4.3 billion. It was spun out as a separate company in 2024 but remains under that ownership structure rather than answering to the public markets or to a foundation.
The free tier stopped being useful in 2021
Free accounts are limited to one device type, so a phone and a laptop no longer sync on the same free account. A password manager that does not follow you between devices is not doing the job that makes people use one.
Weights on this page: Privacy & trust 34% · Features 22% · App quality 18% · Price & renewal 14% · Support & refunds 12%. Formula.
Open source, self-hostable, and the only free tier that is not crippled.
73
Owner
Bitwarden, Inc.
Jurisdiction
United States · Five Eyes
No-logs audit
None — apps audited by Cure53, 2025
Price
from $0.83/mo
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The default answer for most people leaving LastPass, and it imports a LastPass CSV export directly. The client and server code are public, Cure53 audits it annually with the reports published, and the free tier syncs unlimited passwords across unlimited devices — the exact restriction that pushed people off LastPass free. Paid is $10 a year and does not rise at renewal.
US company, so Five Eyes jurisdiction, and it took a $100M growth investment in 2022. The apps are plainer than 1Password's.
Privacy & trust
52
Features
100
App quality
75
Price & renewal
98
Free tier syncs unlimited passwords across unlimited devices
All client and server code is open source
Can be self-hosted on your own machine
US jurisdiction, inside the Five Eyes
Interface is plainer than 1Password or Dashlane
Self-hosting is real work, not a checkbox
Lab test pending — scored on public dataiOS app score 75/100 from 31,601 ratingsFull reviewVisit Bitwarden
The most polished apps, a second secret key, and no free tier at all.
56
Owner
AgileBits Inc.
Jurisdiction
Canada · Five Eyes
No-logs audit
None — apps audited by Cure53, 2025
Price
from $2.99/mo
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The pick if the breach is your reason. Its Secret Key means a stolen vault file cannot be attacked with the master password alone — a 128-bit key held only on your devices is required as well, which is precisely the failure mode that made the LastPass vault theft so damaging years after the fact. Travel Mode removes vaults from a device before a border crossing.
Closed source, no free tier, $35.88 a year, Canadian and therefore Five Eyes, and $620M of venture funding implies an eventual exit.
Privacy & trust
42
Features
66
App quality
58
Price & renewal
90
The Secret Key means a stolen vault cannot be brute-forced from the password alone
Best-designed apps in the category by a distance
Travel Mode removes vaults from a device before a border crossing
Closed source, so the encryption claims cannot be independently inspected
No free tier
Canada is a Five Eyes country
Lab test pending — scored on public dataiOS app score 58/100 from 36,952 ratingsFull reviewVisit 1Password
Swiss, non-profit-owned, open source, with hide-my-email aliases built in.
73
Owner
Proton Foundation
Jurisdiction
Switzerland · Outside the alliances
No-logs audit
None — apps audited by Cure53, 2024
Price
from $2.99/mo · ~$4.49/mo over 3 yrs after renewal
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The choice when you want the owner to be structurally different rather than just better behaved: a Swiss non-profit foundation holds control, the code is open, Cure53 has audited it, and email aliasing runs through SimpleLogin, which Proton also owns. If you already pay for Proton VPN or Mail, it is bundled.
The youngest product here, launched in 2023, and the two-year price rises at renewal from $71.76 to $143.76.
Privacy & trust
73
Features
92
App quality
65
Price & renewal
74
Controlled by a Swiss non-profit foundation
Open source and audited by Cure53
Built-in email aliasing via SimpleLogin, not a bolt-on
Enterprise-first, heavily certified, and it charges extra for the basics.
61
Owner
Keeper Security, Inc.
Jurisdiction
United States · Five Eyes
No-logs audit
None — other audited by SOC 2 Type II, 2024
Price
from $2.92/mo
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The one to look at when the vault is not only yours: per-record encryption keys, the most compliance certifications in the category, and admin tooling designed for organisations rather than bolted on afterwards. Its App Store rating is the highest here across a very large sample.
Breach monitoring and secure file storage are paid add-ons, so the headline price understates it. Closed source, US-based, and the free tier is a 30-day trial on one device.
Privacy & trust
42
Features
60
App quality
77
Price & renewal
94
The most compliance certifications in the category
Zero-knowledge architecture with per-record keys
Excellent App Store rating across a very large sample
Breach monitoring is a paid add-on, not included
Closed source
Free tier is a 30-day trial on one device
Lab test pending — scored on public dataiOS app score 77/100 from 229,924 ratingsVisit Keeper
When to stay with LastPass There is no version of this page that recommends staying. If you were a LastPass customer before the 2022 incident, the safe assumption is that a copy of your vault as it existed then is in someone else's hands, and every password inside it should be treated as compromised regardless of which manager you move to. The one legitimate reason to keep the account open a little longer is a staged migration: keep it until every credential has been rotated in the new manager, then delete it. Migrating is not the fix on its own — rotating the passwords is.
This migration is different
Most switching guides are about money. This one is about a file.
In 2022, an attacker obtained backups of LastPass customer vaults. The password fields inside were encrypted with each user’s master password — but the site URLs were not, so anyone holding those backups can see exactly which services each victim used, and can run offline guesses against the master password with no rate limit and no lockout. That work continues years later, and it gets cheaper every year.
So the question is not only “which password manager is better”. It is “what is the correct order of operations to get out safely”, and the order matters more than the destination.
Do these three things in this order
Change the master password and enable two-factor authentication on the LastPass account. Everything else runs through this account, and it should not still be protected by a password you chose in 2021.
Export, import, delete. The CSV export is plaintext. It should exist for minutes, not days, and it should never touch a synced folder, an email or a cloud drive.
Rotate. Email first, then banking, then anything with a card stored, then everything you have reused. Moving your vault to a new product does not undo a password that was stolen — only changing the password does.
Choosing where to go
Bitwarden is the right default. It is open source, audited annually by Cure53 with the reports published, it imports LastPass exports cleanly, and its free tier does the thing LastPass free stopped doing in 2021: sync across all your devices. Paid is $10 a year, which is a tenth of what some rivals charge.
1Password is the right answer if the breach itself is what frightened you. Its Secret Key is a second 128-bit secret stored only on your devices, so a stolen server-side vault cannot be brute-forced with a master password alone. That is a direct architectural answer to how the LastPass theft played out.
Proton Pass is the right answer if you want the ownership to be different in kind. A Swiss non-profit foundation holds the controlling stake, the code is open, and email aliasing through SimpleLogin is built in rather than bolted on. It is also the youngest product here.
Keeper is the right answer when the vault is shared with colleagues rather than family: per-record keys, deep admin controls and the compliance paperwork enterprises ask for.
Our full password manager ranking scores all of them on the same formula, and explains why LastPass sits on the avoid list rather than the chart.
What “zero knowledge” is worth without an audit
Every product in this category says it cannot read your vault. That claim is either checkable or it is not.
Bitwarden, 1Password and Proton Pass publish independent audit reports. There is no comparable published independent audit of LastPass’s current architecture. After an incident in which vault backups left the building, an unverifiable claim is not a reassurance — it is the same promise, repeated.
After you have moved
Keep the LastPass account alive, empty and locked for a couple of weeks in case something was missed in the import. Then delete it properly through the account-deletion flow rather than just removing the browser extension, which leaves the account and its stored data intact.
Then, once a year, check whether your addresses have appeared in anything new with the email breach checker. Migration is a day’s work. Rotation is what actually closes the hole.
iOS, Android, Mac, Windows, Linux, Browser · not Router, TV
iOS, Android, Mac, Windows, Linux, Browser · not Router, TV
iOS, Android, Mac, Windows, Linux, Browser · not Router, TV
iOS, Android, Mac, Windows, Linux, Browser · not Router, TV
Devices
Unlimited
Unlimited
Unlimited
Unlimited
Countries
—
—
—
—
WireGuard
?
?
?
?
Kill switch
?
?
?
?
Obfuscation
?
?
?
?
RAM-only servers
?
?
?
?
Open-source apps
?
?
?
?
Split tunnelling
?
?
?
?
Multi-hop
?
?
?
?
Port forwarding
?
?
?
?
Ad blocker
?
?
?
?
P2P allowed
?
?
?
?
Free tier
?
?
?
?
Netflix
Unknown
Unknown
Unknown
Unknown
BBC iPlayer
Unknown
Unknown
Unknown
Unknown
Works in China
Unknown
Unknown
Unknown
Unknown
Works in UAE
Unknown
Unknown
Unknown
Unknown
Cash / crypto
No
crypto
No
crypto
Live chat
?
?
?
?
iOS app score
58/100 (4.4★)
75/100 (4.8★)
58/100 (4.7★)
65/100 (4.8★)
Our lab test
Pending
Pending
Pending
Pending
How to switch without paying twice
Change the master password and turn on two-factor firstDo this before exporting anything. Everything that follows passes through the LastPass account, and if that account is still protected by a password from 2021 you are exporting into an open room.
Export to CSV, import, then destroy the fileThe export is plaintext: every password in one readable file. Import it into the new manager immediately, then delete it and empty the trash. Never leave it in Downloads, never email it to yourself, and never keep it on a synced folder.
Rotate the accounts that matter, in orderEmail first, because it resets everything else. Then banking, then anything holding a card, then everything reused anywhere. A migration copies old passwords into a new vault; it does not make passwords stolen in 2022 safe again.
Move your two-factor codes deliberatelyIf LastPass Authenticator held your TOTP codes, re-enrol each account in the new app one at a time and keep the recovery codes somewhere offline until every one is confirmed working. This is where people lock themselves out.
Delete the LastPass account, not just the appRemoving the extension leaves the account and its stored vault in place. Delete the account through LastPass's own account-deletion flow once the new manager has been running for a couple of weeks and you are certain nothing was missed.
Frequently asked questions
Is my LastPass vault still at risk after the 2022 breach?
If you were a customer at the time, assume the encrypted copy taken then can be attacked offline for as long as an attacker cares to try. Strong, unique master passwords with high iteration counts make that expensive rather than impossible, and the unencrypted site URLs in the stolen data tell the attacker which accounts are worth the effort. Rotate the passwords; do not rely on the encryption holding forever.
What is the easiest password manager to switch to from LastPass?
Bitwarden. It accepts a LastPass CSV export directly, the import maps folders and secure notes without manual cleanup, and the free tier syncs across every device so you can move first and decide about paying later.
Is Bitwarden's free tier really enough?
For one person, yes. Unlimited passwords across unlimited devices, sync included, and passkey support. The $10-a-year upgrade adds file attachments, emergency access and integrated TOTP — worth it, but not required to leave LastPass today.
Should I use my browser's built-in password manager instead?
It is better than reusing passwords, and it is worse than any pick here: it ties you to one browser vendor, it rarely offers a real independent audit of the sync layer, and sharing or emergency access is limited. If you are already making a move, make it to a dedicated manager.
How do I move my two-factor codes off LastPass Authenticator?
One account at a time, and never in a hurry. Open each service's security settings, disable and re-enable two-factor with the new app, confirm a code works, and store the fresh recovery codes offline. Do not delete the old authenticator until every account has been re-enrolled and tested.