What it is, and what makes it different
Bitwarden is a password manager that publishes its source code, from the browser extension you install to the server that stores the encrypted blob. Everything in this category claims it cannot read your vault. Bitwarden is one of the few products where somebody outside the company can check.
It was founded in 2016, which makes it younger than 1Password and LastPass, and it arrived without the marketing budget of either. What it had instead was a free tier that did not treat free users as a funnel, and that is still the single most important thing about it.
Ownership and jurisdiction
Bitwarden, Inc. is independent, with no parent company and no private-equity owner. In this market that is genuinely rare. It is also incorporated in the United States, which places it inside the Five Eyes, and in 2022 it took a $100M growth investment led by PSG.
We do not treat the investment as disqualifying, and we do not pretend it is nothing. Growth capital at that size is not charity. It comes with an expectation of a return, which eventually means a sale or a listing, and the company that holds your vault in 2032 may not be governed the way the one that holds it today is. That is the honest shape of the risk, and it applies to every venture-backed manager, 1Password included.
The counterweight, and it is a real one, is that the code is public and the product is self-hostable. If the company changes character, the exit is not theoretical. That is not true of any closed-source alternative.
Audits
Cure53 has audited Bitwarden in 2023, 2024 and 2025, covering the applications and related components, and the reports are published rather than summarised. Annual, external, and readable is the standard the rest of the category should be held to, and most of it is not.
Audits are a snapshot of a codebase at a date, not a guarantee about the build you install next month. Combined with public source, though, they are the strongest available evidence for a claim that otherwise has to be taken on faith.
The licensing argument, stated plainly
In late 2024 Bitwarden introduced a software development kit component under a licence that restricted how it could be used, and because the desktop and browser clients came to depend on it, a large part of the community concluded that the clients were no longer meaningfully open source. The criticism was loud and specific, and it came from the exact users who had chosen the product for that property.
Bitwarden responded by restructuring the arrangement so the affected code moved to a licence the community accepted, and the dispute closed. We record it here because reviews that omit it are telling you a company has a property it in fact has a policy about. The outcome was good. The lesson is that open source is maintained by pressure, and the pressure worked because the code was public enough for anyone to notice.
What it costs
| Plan | Intro | Renewal | True cost per month over 3 years |
|---|---|---|---|
| Free | $0 | $0 | $0 |
| Premium (1 year) | $10.00 | $10.00 | about $0.83 |
| Families (1 year) | $40.00 | $40.00 | about $3.33 |
There is no intro-then-renewal trick here. The renewal price equals the first-year price on both paid plans, so the three-year cost is simply three annual payments. Premium at roughly $0.83 a month over three years is a third of what Proton Pass Plus works out to and about a quarter of 1Password Individual. Our true cost calculator exists because most of this market does not price this way.
A 30-day money-back window applies, and cryptocurrency is accepted, which is a small but genuine privacy affordance at signup.
Features, and where it is plainer
Passkeys, end-to-end encryption, a usable offline vault, breach monitoring, secure sharing, emergency access, family plans, and browser extensions across the major browsers. Apps for iOS, Android, macOS, Windows, Linux and the browser. Self-hosting is supported and documented.
The interface is the weak point, and it is fair to say so. Bitwarden looks like a tool. Autofill works, organisation is functional, and nothing about it is delightful. If you are moving somebody non-technical off sticky notes, the polish gap against 1Password is a real adoption cost rather than a matter of taste.
Self-hosting, honestly
Self-hosting is the feature that makes the jurisdiction question answerable, and it is also the one most likely to be recommended carelessly. Running the server yourself means you own the backups, the upgrades, the TLS certificates and the uptime. A vault you cannot open because your home server died while you were abroad is a worse failure than any of the risks self-hosting removes.
Our position is that it is excellent for people who already run infrastructure and poor advice for anyone else. The hosted service with a strong master password is the right default.
Who it is for
Someone setting up a password manager for the first time, or migrating from a browser, who wants a product they can keep for a decade without being upsold. Someone who wants the encryption claim to be checkable rather than promised. Someone who wants to spend $10 rather than $36 a year. And, separately, someone technical who wants the server under their own roof.
If Five Eyes jurisdiction is a hard line in your threat model, Proton Pass under Swiss non-profit control is the alternative that answers it, at a higher price and with a shorter history. The full ordering is on our best password managers page, and the password generator here will produce a master password worth protecting.
What we have not tested
We have not run our own hands-on testing of Bitwarden. Import fidelity from other managers, autofill reliability across browsers, and recovery from a lost device are all things we intend to test and have not. No number on this page comes from a measurement we made. The pending dimensions of the score stay pending until that work is done and published.



