Most searches for a LastPass alternative begin with 2022, when an attacker copied customer vault backups and took the website URLs in them unencrypted. The people looking are usually existing customers whose security team has asked the question, plus new buyers avoiding that history. They move to managers with open source code or a stronger key model.
Pricing: Free plan for one user on one device type; business plans per user per month, published
Established in: United States
Built for: An organisation already deployed on it and managing the migration cost
Not for: Any new deployment with a free choice
01
Why buyers look past LastPass
01
The 2022 breach is part of every review
LastPass's own notice says a backup of customer vault data was copied in 2022, with passwords encrypted but website URLs, email addresses and billing details readable. A security review cannot simply move past that, which means each renewal now involves explaining to an auditor or a board why the organisation is staying.
02
Trust is the product in this category
A password manager is bought on confidence in the vendor's security engineering, and trust in LastPass has not fully recovered. It has since raised its key derivation to 600,000 PBKDF2 rounds, and the software remains competent, but competence is not the thing customers are paying for when they hand over every credential they have.
03
A new buyer has no reason to choose it
LastPass fits organisations already deployed and weighing the migration cost, not a new deployment with a free choice. Its Teams plan is $4 per user per month for up to 50 users. Bitwarden Teams costs the same, and Keeper, NordPass and Proton Pass list entry plans at lower per-user prices, without the history attached.
Free for personal use; paid per user per month, published, low
#11
you already run Zoho and cost outweighs audit history
03
What each one does differently
1
Bitwarden
United States · Free personal tier; business plans per user per month, published
Bitwarden answers the trust question LastPass struggles with by publishing the code: clients and server are open source and audited independently each year. It can be self-hosted, and Teams is listed at $4 per user per month, the same as LastPass Teams. The admin console is plain.
Switch from LastPass if you want encryption claims you can inspect, at a similar price.
Canada · Per user per month, published; flat-price Teams Starter Pack for up to 10; 14-day trial
1Password encrypts with two secrets, and its 128-bit Secret Key never reaches the vendor, so stolen server data cannot be cracked by guessing a master password, a direct answer to the LastPass scenario. It is the best-designed manager here, though closed source and priced at $8.99 USD per user.
Switch from LastPass if you want the strongest answer to a stolen vault and high staff adoption.
Dashlane gives administrators the most actionable reporting on weak, reused and breached credentials, which helps a team that must show things improved after leaving LastPass. Passkey support is ahead of most rivals. It is closed source and priced above Bitwarden.
Switch from LastPass if you need to evidence credential hygiene to management after the move.
United States · Per user per month, published; add-ons extra
Keeper lists FedRAMP High authorisation, SOC 2 Type 2, ISO 27001 and FIPS 140-3 validation, and enforces sharing rules by role, which gives a former LastPass customer paperwork to show an auditor. Plans run from $2 to $6 per user per month; BreachWatch and Secrets Manager are add-ons.
Switch from LastPass if the replacement has to satisfy a compliance checklist.
Lithuania · Free personal plan for one user; business plans per user per month, published; Teams sold as a 10-user pack
NordPass is close to a like-for-like hosted replacement for a small LastPass team: a ten-user Teams pack at €1.99 per user per month, a 14-day trial, a simple admin view, and ISO 27001 and SOC 2 Type 2 certification. Integrations are fewer, and the parent company sells many adjacent products.
Switch from LastPass if you are a small team wanting a quick, inexpensive move.
Switzerland · Free tier; paid per user per month, published
Proton Pass publishes its apps on GitHub, is based in Switzerland where LastPass is a United States vendor, encrypts web addresses along with every other field, and builds in email aliases. It is the youngest manager in the category; SSO and SCIM need its Professional plan.
Switch from LastPass if privacy and jurisdiction are what your review cares about.
Germany · Free self-hosted community edition; hosted plans published
Psono removes the vendor-held vault that the LastPass breach exposed: it is open source and runs on your own servers, with a free community edition. Interface and mobile apps lag the commercial tools, and you patch and back up the server.
Switch from LastPass if you have concluded that no vendor should hold the vault.
India · Free for personal use; paid per user per month, published, low
Zoho Vault is the cheapest credible team option, with shared folders, role-based access and directory provisioning. For a buyer leaving LastPass over trust it has a weakness of its own: less independent audit history than the specialist vendors.
Switch from LastPass if you already run Zoho and cost outweighs audit history.
Staying with LastPass is defensible for an organisation already deployed on it, where the software works, staff know it and the cost of migrating everyone is real. It remains competent, with a large installed base, and its Business plan includes three SSO apps, with unlimited SSO in Business Max. The condition is that the security team has examined the 2022 breach and recorded why staying is acceptable.
05
What moving off LastPass involves
01
Rotate, do not just relocate
Because vault backups were copied in 2022, moving the same passwords into a new manager leaves the old exposure in place, and the stolen URLs show an attacker which sites to try. Plan to change the credentials that matter most as part of the migration, starting with administrator accounts and anything shared across a team.
02
Shared folders are the fragile part
Personal logins are the easy half. Shared credentials carry permissions that may not survive an export. List who can see what beforehand, recreate those groups in the new product first, and confirm each shared item survives if the person who created it has since left.
03
Handle the export file with care
An export is every credential in readable form. Decide who runs it, on which device, and how the file is destroyed afterwards. Where possible let each user import their own vault so that no single file containing the whole organisation's passwords ever exists.
06
Questions about replacing LastPass
5 answers
Is LastPass still safe to use?
LastPass encrypts vaults on the device with AES-256 and now uses 600,000 PBKDF2 rounds, but the backups copied in 2022 cannot be recalled, and an old, weak master password leaves that copy exposed.
It is a judgement for your security review; for a new deployment with a free choice we do not recommend it.
What is the best free alternative to LastPass?
LastPass Free is limited to one device type. Bitwarden's free plan is the usual pick, because both clients and server are open source and audited annually.
Proton Pass Free covers unlimited logins and devices with ten email aliases. NordPass Free is for one user without multi-device access.
Should a business move from LastPass to 1Password or Bitwarden?
Choose 1Password if adoption is the main risk, since it has the best interface and a Secret Key that protects stolen server data.
Choose Bitwarden if the review wants open source, annual audits or self-hosting. Bitwarden Teams is $4 and 1Password Business $8.99 USD per user per month.
How hard is it to migrate away from LastPass?
The mechanical step is an export and an import. The effort is in recreating shared folders and permissions, rotating important passwords, and getting staff used to a new extension.
That migration cost is the main reason existing LastPass customers weigh staying, so run a pilot group first.
What exactly was exposed in the LastPass breach?
According to LastPass's notice, an attacker copied a backup of customer vault data. Usernames, passwords, secure notes and form data stayed encrypted with 256-bit AES.
Website URLs were unencrypted, as were company names, billing addresses, email addresses, phone numbers and IP addresses. Master passwords were not stored and not taken.