A password manager: an encrypted vault synchronised across devices, with autofill, passkeys, secure sharing and recovery for families and teams.
Do not build this. Keep paying, and read why — the reason matters more than the verdict. A password manager holds every account you own. Its cryptographic design has been audited repeatedly by people who do this professionally, and the failure mode of getting it wrong is not a bug, it is every account you have. There is no version of this where a homemade one is a reasonable risk. WHAT TO DO INSTEAD - Keep it, or move to Bitwarden, which is open source, audited, cheaper, and can be self-hosted if you insist on holding the data - Either way, do not write the cryptography WHAT YOU CAN BUILD, AND SHOULD An auditor over your own vault, using the manager's own export or command-line tool. Node 20+, a script, no server, nothing stored: - Reused passwords across accounts, ranked by how sensitive each account is - Passwords not rotated in a long time, on accounts that matter - Accounts with no second factor where the service supports one, checked against a public list of which services do - Entries whose domain no longer resolves or now redirects elsewhere — a login for a company that was acquired is a login on somebody else's system - Weak passwords by entropy, and any that appear in a breach corpus, checked with k-anonymity so the password never leaves your machine - A report you act on once a quarter Run it locally, never store the export, and delete it when the script finishes. Write that into the script itself rather than trusting yourself to remember. THE OTHER THING WORTH DOING Rehearse recovery. If you lost your phone and your laptop today, could you get back into the vault? Most people have never checked, and the answer is what actually decides whether a password manager is protecting them or holding them hostage. Print the emergency kit, put it somewhere physical, and test it once. THE ONE-LINE VERSION The audits and the recovery path are the product. Build the auditor, not the vault.
What you lose
- A cryptographic design that has been audited repeatedly by people who do this for a living
- Native apps and browser extensions on every platform, with autofill that works on real sites
- Secure sharing, recovery and family or team administration without weakening the model
- Breach monitoring, passkey support and the secret key that makes a stolen vault useless
- Someone else’s responsibility for a bug that would expose everything at once
If you would rather not build
- Bitwarden — paid, cheapest audited alternative
What it costs
as published on their pricing page
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $3.99/mo | — | — |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Vaultwarden
$0Bitwarden-compatible server that runs on a small machine, used with the official clients.
dani-garcia/vaultwardenfree · open source
KeePassXC
$0Offline encrypted vault in a single file, synchronised however you like.
keepassxreboot/keepassxcfree · open source
Why this verdict
our own opinion · changed only by a person
12/100
Verdict no at 12: this is the clearest no on the list. Vaultwarden is a legitimate self-hosted path and the prompt sets it up carefully, but writing the cryptography yourself has no acceptable failure mode, and the clients are the hard part regardless.
History
tracked since 9 Aug 2026 · nothing is ever overwritten
Questions about 1Password
answered from the record above
Is 1Password free?
No — the plan we track is $3.99 a month. Individual at $3.99/month billed annually; Families is $6.95/month for five people, Teams is priced per user.
Can you replace 1Password by building your own?
KEEP IT. The value is the network, the data or the infrastructure. Keep paying. Replacement score 12 out of 100, build time longer than it saves. Read what you lose before you decide.
How much does 1Password cost?
$3.99 a month on Individual — $47.88 a year. Recorded 9 Aug 2026.
What do you lose by replacing 1Password?
A cryptographic design that has been audited repeatedly by people who do this for a living; Native apps and browser extensions on every platform, with autofill that works on real sites; Secure sharing, recovery and family or team administration without weakening the model; Breach monitoring, passkey support and the secret key that makes a stolen vault useless; Someone else’s responsibility for a bug that would expose everything at once. If any of those carry weight for you, keep paying.
Is there an open-source alternative to 1Password?
Yes: Vaultwarden, KeePassXC. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

