Price captures verified 2026-08-09; overall scores unpublished

How Password Managers Work

Vault, then autofill: a password manager keeps unique site passwords in an encrypted vault you unlock with a master password (plus MFA), then offers those secrets through official apps and extensions. It does not make phishing or malware disappear, and vendor zero-knowledge claims stay claims until you read primary sources. Stop reuse and turn on MFA for email first. Optional paid cards use claim-ledger prices from 2026-08-09 (NordPass Premium from $1.39/mo on a 2-year USD plan; 1Password Individual $2.99/mo billed annually; Bitwarden Premium $1.65/mo billed annually for comparison-only diligence). Overall scores stay unpublished. Who should not buy: anyone who skipped free hygiene, or who needs a published lab score before deciding.

  • Guide · Educational · ~12 min read

Direct definition

A password manager is software that stores login credentials in an encrypted vault unlocked by a master password (and usually MFA), then fills unique site passwords through official apps or browser extensions so you do not reuse the same secret across services.

Key takeaways

  1. 1Read the vault model below so you know what you are buying
  2. 2Create a long unique master password you will not reuse elsewhere
  3. 3Stop new password reuse today (browser generator is fine as a bridge)
  4. 4Enable MFA on email and on any vault you install
  5. 5Practice unlock and autofill on two low-risk sites before banking
  6. 6Open the Password Manager Finder only if sync or sharing still hurts
Start Password Manager Finder →

How it works

  1. 1

    The vault model in plain language

    Free

    Your vault holds logins, notes, and sometimes passkeys. A master password unlocks ciphertext on your devices according to the vendor’s model. Marketing that says the vendor “cannot see your passwords” is a claim to verify on trust/security pages, not a guarantee we invent here.

    • One vault account, not three half-used apps
    • Memorize a long unique master password
    • Enable MFA on the vault itself
  2. 2

    Autofill and password generators

    Free

    Official extensions and apps detect login forms and can generate long random passwords per site. Autofill is a convenience layer; if a site breaks autofill, copy from the vault carefully. Never install lookalike extensions from ads.

    • Install only from official vendor pages or app stores
    • Generate a unique password when changing a reused one
    • Avoid saving banking secrets in plain notes apps
  3. 3

    Sync, devices, and recovery

    Free

    Cloud sync keeps phones and laptops aligned and creates recovery and device-list responsibilities. Review trusted devices, remove old phones, and practice recovery before an emergency. A vault nobody can recover is a household risk.

    • Review the trusted-device list monthly at first
    • Store recovery codes offline (not in the vault alone)
    • Keep apps updated from official channels
  4. 4

    What a manager does not do

    Free

    It does not replace MFA, antivirus hygiene, or phishing caution. It does not prove a vendor is breach-proof. It will not fix accounts you still share in chat. Treat “unlimited devices” and similar slogans as plan marketing until you confirm current plan cards.

    • MFA on email remains mandatory
    • Bookmark real unlock URLs; beware lookalikes
    • Share only through vault features, never SMS passwords
  5. 5

    When a paid product is justified

    Optional paid

    Pay when browser storage cannot cover cross-browser sync, intentional sharing, or recovery you trust. NordPass fits a simpler personal upgrade (Premium from $1.39/mo on a 2-year USD plan, 2026-08-09). 1Password fits structured sharing (Individual $2.99/mo billed annually the same day). Bitwarden remains useful free/open-source research at Premium $1.65/mo billed annually (comparison-only, no /go/ deal).

    • Confirm the job is sync/sharing, not one reused email password
    • Read who should not buy on product pages
    • Use /go/ only for pack merchants you choose

Limits of this explainer

  • The need to trust official apps and keep them updated
  • Sites with broken autofill that still need careful manual entry
  • Recovery processes you must practice before an emergency
  • Phishing that captures a master password on a fake unlock page
  • Invented encryption grades or unpublished audit scores

Sources

  • Security Checklist methodology, Educational guides stay free-first; scores unpublished until test records exist
  • NordPass claim ledger, data/claim-ledgers/nordpass.json#nordpass-starting-price; Premium from $1.39/mo (2-year USD via NordSec GraphQL) captured 2026-08-09
  • 1Password claim ledger, data/claim-ledgers/1password.json#1password-starting-price; Individual $2.99/mo billed annually captured 2026-08-09
  • Bitwarden claim ledger, data/claim-ledgers/bitwarden.json#bitwarden-starting-price; Premium $1.65/mo billed annually; comparison-only (2026-08-09)
  • Claim ledgers (T014), nordpass.json, 1password.json, bitwarden.json, dashlane.json: starting prices verified 2026-08-09; scores unpublished
  • Vendor marketing pages, Feature and architecture claims from official sites, not independent lab evidence; re-verify same-day before purchase advice
  • Security Checklist methodology, How password-manager reviews are structured before scores publish, /methodology/

Next steps

Frequently asked questions

Internal links

Continue in this cluster

Hub, tools, and related pages from the inventory. No invented URLs.

Expert guides & insights

Related guides

Stay in the same problem space without jumping brands.

Want launch updates?

The email newsletter is not running yet. Use Contact if you want a human reply when it opens. No fake signup form.