f you’re still using the same password for everything, Jef van de Graaf has you covered: “I’m still using LadiesMan123$ as my password for EVERYTHING since I learned about the internet. Never been hacked. Never lost a dime.” (We think he’s joking. We hope he’s joking.)
For everyone else, a password manager is one of those tools where the stakes are unusually high. It’s not just about convenience — it’s about the security of every client site, every hosting account, every credential you’ve ever touched. Picking the right one matters, and switching is a pain.
The Most Mentioned Password Managers
These tools came up repeatedly in the discussion:
A handful of other tools came up as well (we’ll get to those).
Why Agencies Choose These Password Managers
1Password
The most recommended password manager in this community — by a wide margin.
1Password came up more than any other tool in the thread, and the loyalty runs deep. Several members have been using it for over a decade. The reasons they give are consistent: it’s stable, it handles team sharing well, and it just works without friction.
“1Password lets me save social logins and automatically log me in without having to manually choose between multiple Google accounts. It can also automatically fill in and submit my 2FA codes without any extra touch. It also supports custom fields, which I love the most. I’ve used NordPass, LastPass, and Bitwarden before, but I still prefer 1Password over all of them.”
Faisal Ahammad
“1pass just works. My only gripe with it is that I have to manually share folders. I can’t add an admin and have them access all folders at once.”
Melodie Moore
“Perfect for teams, and we can share 2FA codes with the entire team so everyone has access and I am not the bottleneck.”
Blake Whittle
Alex Celeste gave the most thorough breakdown in the thread — using 1Password for everything from server details and database credentials to SSH keys, API credentials, software licenses, passkeys, and even CLI access for AWS and DigitalOcean tools. For power users, the depth of what 1Password can store goes well beyond just passwords.
The most common origin story: switched from LastPass after the security incidents and never looked back. Kevin LeMasters is still on LastPass with his team but specifically called out 1Password’s subdomain handling and 2FA sharing as the two features pushing him toward making the switch.
Best fit: agencies of any size who want a polished, stable tool with strong team sharing and 2FA integration.
Bitwarden
The open-source alternative that earns serious trust.
Bitwarden was the second-most mentioned tool in the thread — and the enthusiasm for it was genuine. The combination of open-source transparency, third-party security audits, and an affordable price point makes it a compelling choice, especially for those who want to verify rather than just trust.
“I chose it because it was open source, had third-party security reviews, and was inexpensive. I also appreciated that it has a clean, simple interface.”
Patrick Boehner
“Bitwarden Family plan where I can share credentials including 2FA codes. It’s beautiful.”
Michal Krakowiak
“Switched from LastPass and it was a great decision: better UI and more features including the OTP management.”
Daniele Besana
For those who want even more control, Vaultwarden came up multiple times as the self-hosted alternative. Rose Newell runs it on her own server with a Raspberry Pi backup — zero downtime, full ownership of the data. Daniele Besana’s team of 10 runs it on an inexpensive VPS. Thiago de Carvalho moved his whole team to self-hosted Vaultwarden and called it “the best decision.”
Dustin Dauncey is one of the few holdouts — he’d consider switching from 1Password to Bitwarden or Vaultwarden if they added tagging functionality, which he relies on heavily.
Best fit: agencies who want open-source transparency and affordable pricing — or those comfortable self-hosting who want full data ownership.
RoboForm
The long-timer’s pick — decades of reliability with zero drama.
RoboForm has a quietly devoted following in this community. The members using it tend to be long-time users who’ve never had a reason to leave — and that’s kind of the point.
“Using Roboform since 2018. They have never had a security breach in their 20+ year history. Also, almost no errors or bugs of any kind.”
Vojkan Cvijanovic
“Roboform for 20 years…”
Dennis Gram
“Been using it for 15+ years. Except a few annoying things, it works great and all devices are synced. Like their Identity feature as well.”
Anil Agrawal
The unbroken security track record comes up consistently as the primary reason people stay. RoboForm has been around longer than most of its competitors and has never had a major breach — something that’s harder to say about some of the more prominent names in the category.
Best fit: agencies who prioritize a long, clean security track record and want something that reliably stays out of the way.
Proton Pass
The privacy-first pick from a trusted European ecosystem.
Proton Pass came up frequently — and almost always in the context of the broader Proton suite. Members aren’t just choosing Proton Pass for passwords; they’re choosing Proton as a philosophy.
“I use Proton Pass… and all of their products as I try to move away from Google’s data-sucking products.”
Mike Mubanga
“Proton. Swiss owned. Part of my drive to use European services.”
Edith Allison
“I currently have Proton Pass and 1Password — both simultaneously. Bit more partial to the Proton suite.”
Ajay D’Souza
David Bishop has been a long-time RoboForm user but has been testing Proton Pass lately — noting a few UI rough edges but calling it otherwise solid. The migration path is straightforward: export from your browser or current manager, import into Proton. Christiaan Bruinsma confirmed it supports imports from multiple providers including Google.
Best fit: agencies prioritizing privacy, data sovereignty, and European hosting — especially those already using Proton Mail or Proton Drive.
Dashlane
The team-management pick with a clean security record.
Dashlane came up several times, with Luke Humble making the most detailed case for it: it was one of the few password managers with no history of being compromised, and the team sharing and credential management features were the deciding factor.
“I chose it mainly because it was one of the very few that hadn’t actually been compromised in its history, but also the ease of use and control over sharing of credentials with team members and contractors.”
Luke Humble
“Dashlane Family Plan! My family and my parents are all on it and I have extra spaces for colleagues I need to add temporarily for projects or vacation coverage. Been using it for countless years and ZERO complaints thus far!”
Karen Dec
The one counterpoint: Melodie Moore tried it when switching from LastPass and gave up after a week, citing painful onboarding and team management. She acknowledged that was years ago and might be worth revisiting — though she added that anyone still on LastPass is “in an abusive relationship.”
Best fit: agencies who want a clean security history and strong team credential sharing, particularly for mixed teams of employees and contractors.
Keeper Security
The enterprise-grade option for granular control.
Keeper Security came up from several members, consistently positioned as the step up from 1Password when you need more sophisticated sharing and organizational structure.
“Keeper Security all the way. It’s amazing for working with teams because you can have passwords in folders, passwords for roles. You can reclaim all the passwords when someone leaves your team and you retrieve them from that user.”
Pol Cousineau
“We recently moved from 1Password to Keeper for better sharing granularity and organisation.”
Matthew Temple
Abbas Muraj highlighted Keeper’s passkey sync support as a specific win for agencies dealing with multiple Microsoft 365 tenants and SaaS applications.
Best fit: agencies with larger teams who need role-based access, clean offboarding when team members leave, and fine-grained control over who can see what.
KeePass / KeePassXC
The no-cloud, no-subscription option for the control-minded.
KeePass and its cross-platform fork KeePassXC came up from members who are fundamentally skeptical of storing passwords in someone else’s cloud — and want the database to live on their own hardware.
“Keepass. Hosted password services are asking for trouble.”
Blake Howe
“KeePass XC. It’s free, open-source and works on all platforms. The Firefox addon works well. It doesn’t sync to the cloud but I don’t want this anyway.”
Jean Werk
Manuel Serrenti runs KeePass on Windows, KeePassXC on Mac, and KeePass2Android on mobile — all syncing to a single database file stored on Google Drive, keeping everything in sync across five devices with no subscription. He notes that swapping out Google Drive for FTP or WebDAV is easy if he ever wants to move off Google entirely.
Best fit: agencies or individuals who want full local control of their password database, no subscription costs, and no dependency on a third-party cloud service.
Notable Mentions
These also came up in the thread:
- NordPass — mentioned by Naz Haque; a clean, simple option from the Nord Security family
- Sticky Password — Jennifer Beam’s pick; a lesser-known but long-running option
- HyperVault — a European-based digital vault that came up from Thierry Dupont; worth a look for those prioritizing EU hosting
- Locker — Hamza El’s pick, alongside his own experiments building credential handoff for AI agents
- HeyLogin — Usman Latif uses it alongside Dashlane and Apple Passwords
- Apple Passwords — came up as a companion tool for a few members already deep in the Apple ecosystem
- Passbolt — Alberto Olivera’s pick; an open-source, self-hostable option built specifically for teams
The LastPass Situation
It would be impossible to summarize this thread without acknowledging the elephant in the room: LastPass.
Almost every member who mentioned 1Password, Bitwarden, or Dashlane noted they switched from LastPass — usually after the security incidents in 2022, when encrypted password vaults were confirmed to have been stolen. Cathy Lynch Sirvatka, Eric Tank, Dave Porter, Rob Marlbrough, Patrick Boehner, and Daniele Besana all told the same story: LastPass, then a breach, then a switch that they all said they should have made sooner.
A few members are still on LastPass. Ben Wade has been on it since the beginning with no personal issues. Gerhard Reus admitted he’s only still there because he’s lazy and would “probably choose Bitwarden” if he made the move. Darlington Okafor mentioned it without elaboration.
Alison Monday has a free LastPass account specifically to receive shared logins from clients who use it — but uses 1Password for everything else. That’s probably the most practical approach if you’re fully moved off but still work with clients who haven’t.
Patterns We Noticed
A few things stood out across the whole thread:
- The LastPass exodus is real and mostly complete. Of all the members who mentioned LastPass, nearly all of them are former users — not current ones. The 2022 incidents clearly shook the community, and most people made the switch within a reasonable window after.
- 1Password and Bitwarden have split the market. Those two tools accounted for the vast majority of mentions. They serve slightly different profiles — 1Password tends to win on polish and team UX, Bitwarden on open-source trust and price — but both are genuinely excellent.
- Self-hosting is gaining ground. Vaultwarden came up multiple times from members running their own instances. The appeal is clear: you own the data, you control the uptime, and the cost is essentially just a VPS. For technically comfortable agencies, it’s an increasingly attractive option.
- Privacy concerns are driving tool choices. Proton Pass isn’t just a password manager to the people using it — it’s part of a broader effort to move away from US Big Tech infrastructure. That motivation came up explicitly from multiple members.
- Security history matters more than features. Multiple members specifically cited a clean breach record as the reason they chose or stayed with their tool. In a category where the whole point is keeping things secure, that’s not a surprising priority — but it’s worth noting how often it came up unprompted.
- The best password manager is the one you’ll actually use. Patrick Boehner put it perfectly: “Whichever one you will use consistently. The number of clients who have password managers but use them rarely or still write their own passwords.” Feature debates are secondary if the tool doesn’t get used.
How to Choose the Right Password Manager
If you’re evaluating options, here are the questions that came up again and again in this thread:
- Do you need to share passwords with a team, and how granularly?
- Do you want an open-source tool with verifiable security, or are you comfortable trusting a proprietary product?
- Are you comfortable self-hosting, or do you want a fully managed cloud service?
- Is privacy and data sovereignty a priority (points toward Proton Pass or European-hosted options)?
- How important is the mobile and browser experience day-to-day?
- Does your pricing model work at the team scale you’re operating at?
Frequently Asked Questions About Password Managers
What is the best password manager for WordPress agencies? 1Password and Bitwarden were the two most recommended tools in this community. 1Password tends to win on polish, team UX, and 2FA handling. Bitwarden wins on open-source transparency, affordability, and the option to self-host. Either is a strong choice.
Is LastPass still safe to use? Most of the agency owners in this thread have moved away from LastPass following the 2022 security incidents, in which encrypted vaults were confirmed to have been stolen. While LastPass has made changes since then, the community consensus is that better alternatives are available and the switch is worth making.
What’s the best free password manager? Bitwarden has a genuinely capable free tier and is the most commonly recommended free option. KeePass and KeePassXC are also free and open-source, though they require more manual setup and don’t sync to the cloud automatically.
What’s the best password manager for teams? 1Password, Keeper Security, and Dashlane all came up specifically for their team features. Keeper was highlighted for role-based access and clean offboarding when team members leave. 1Password was praised for 2FA sharing and subdomain handling. Dashlane for its ease of adding temporary collaborators. Bitwarden (and its self-hosted Vaultwarden version) also works well for teams, with members running it for teams of 10+.
What is Vaultwarden and should I use it? Vaultwarden is a lightweight, open-source, self-hosted server that is compatible with all the official Bitwarden apps. It lets you run your own Bitwarden-compatible server on a VPS or home server. Several members in this thread run it for their teams and love it. It’s a great option if you’re comfortable with self-hosting and want full control over your data — but requires more setup and maintenance than a managed cloud service.
