We evaluate password managers by checking whether they reliably save and replay credentials, protect and manage a vault, fill forms, and generate distinct passwords—then assessing how those tasks work across supported devices, alongside security evidence, usability, recovery, and plan value. A recommendation should reflect documented tests, not a vendor’s feature list alone. This page explains the criteria and evidence we use; it does not claim hands-on results for any particular product.
What we test in a password manager
Each evaluation should use a defined set of tasks and report what was actually tested. The core is whether the manager handles the credentials people rely on, securely and consistently.
As an Amazon Associate I earn from qualifying purchases.
- Credential capture and replay: Check whether the manager can save login details and return them when the user needs to sign in again.
- Vault behavior: Examine how the service describes encryption and vault protection, and distinguish documented design from behavior a reviewer could directly observe. A user-facing test cannot, by itself, verify every security property of the underlying system.
- Form filling: Try autofill on representative login forms, noting whether fields are identified correctly and whether the user can control when credentials are submitted.
- Password generation: Check whether the generator can create distinct passwords and whether its available settings are clear and usable.
These areas align with functions PCMag says it evaluates in its password-manager testing methodology. They describe what a review should examine, not results for a specific product.
Recommended Free Tools
How we assess apps, extensions, sync, and autofill
A password manager should be assessed in the environments it supports, rather than inferred from one browser or device. A review should name the operating systems, devices, browser versions, extension versions, and length of testing so readers can understand the scope.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Install and set up the supported desktop and mobile apps and browser extensions included in the test.
- Test saving, retrieving, and filling credentials on representative login pages in supported browsers.
- Check whether changes made on one device appear on another, and record any failures or delays observed during the stated test period.
- Where the product offers multifactor authentication or biometric unlock, test only the options and device combinations actually available to the reviewer.
- Record the duration and frequency of use; do not turn a short or limited test into a claim of universal reliability.
Security.org describes a separate approach that includes multi-week daily use, desktop and mobile autofill, sync, extensions, two-factor authentication, and biometrics. That is an example of another publisher’s process, not a claim about tests conducted here. See its password-manager review methodology for context.
What security and privacy evidence we check
Security claims need to be separated by evidence type. A provider’s description of its architecture is a claim to assess; it is not the same as an independent verification. Reviewers should examine available documentation and explain what they could and could not confirm.
Rank #2
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
- Architecture and protection: Review published security documentation, including how the provider says vault data is protected and what information its systems handle.
- Authentication: Record available multifactor authentication options and test compatibility only for combinations that were actually evaluated. NIST’s guidance discusses multifactor cryptographic authenticators, but it does not establish that a particular security key works with a particular password manager.
- Privacy: Read the privacy terms for data collection, use, and sharing, and summarize material terms rather than treating a privacy label as proof of security.
- Audits and incidents: Note publicly available independent audit evidence and incident disclosures, identifying their scope and date where possible. The existence of an audit does not show that every feature or later version was assessed.
- Verification limits: State which points came from vendor documentation, public disclosures, or direct testing, and identify important questions the review could not independently verify.
PCMag says its methodology considers policies, incident responses, and multifactor authentication as well as product functions. A review should make those checks useful to readers without implying that its process certifies a service.
How we evaluate usability, recovery, and migration
Security features matter only if people can use them in ordinary account workflows. We assess onboarding and routine tasks in the tested environments, then document the results rather than generalizing from an untested path.
Rank #3
- Record how account setup and initial vault use work, including any steps that are confusing or difficult to complete.
- Try routine tasks such as adding, editing, and retrieving a login.
- Where tested, document migration from another manager and the available export process, including relevant limitations or friction.
- Identify available support channels and the specific options checked; do not imply that a response time or support outcome is typical based on a single interaction.
How we compare features, plans, and value
We compare practical features and plan limits alongside usability and security, but a larger feature list is not a security result. For any changing price or plan claim, a published comparison should identify the date and geography it applies to and specify what is included.
- Describe features that matter to the stated use case and indicate which were tested versus merely documented.
- Compare free and paid plan limits, supported devices, and support access where those details are established.
- Date prices and note the relevant region, billing terms, and whether a figure is promotional or recurring.
- Explain the tradeoff behind a value judgment, such as a plan limit that affects a particular reader, rather than relying on feature count alone.
How we score and disclose the testing scope
There is no universal scoring formula established by the published methods cited here. If a review uses a numerical score, it should disclose the criteria and weights so readers can understand how the result was reached. Comparisons should use the same test set and time window wherever possible, and clearly identify exceptions.
Rank #4
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Every product review should state the actual test scope: devices, operating systems, browsers, app and extension versions, duration, tasks, and any limitations. If an item, workflow, security-key pairing, or platform was not tested, say so. Do not invent test counts, reliability rates, compatibility, performance measurements, or personal experience.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →How NIST guidance relates to password-manager testing
NIST Special Publication 800-63B-4, published in July 2025, says users may use password managers to maintain distinct passwords. It also says systems should support autofill for safe retrieval of secrets and recommends allowing copy and paste for people using other password-storage tools. The guidance is for digital identity systems; it is not a certification or endorsement of any consumer password manager. NIST’s SP 800-63-4 Implementation Resources FAQ states: “SP 800-63B-4 requires verifiers to allow the use of password managers and autofill functionality.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




