Think Your Password Manager Is Totally Safe? Here's What You Should Actually Check
Password managers are one of those tools that feel inherently trustworthy. You hand them the keys to your entire digital life, they lock everything up, and you move on. But when was the last time you actually peeked inside and asked: what exactly is this thing storing?
Spoiler: it's probably more than just usernames and passwords.
This isn't a reason to panic. Password managers are still one of the best security habits you can have. But a quick audit — maybe 20 minutes, tops — can make a real difference in how much exposure you actually have. Let's walk through it.
Start With the Vault Itself
Open up your password manager and do a full scroll through your saved entries. This sounds obvious, but most people haven't done it in months (or years). What you're looking for:
- Dead accounts. Old logins for services you don't use anymore — forums, apps you deleted, email addresses you abandoned. These are clutter at best and a liability at worst. Delete them.
- Duplicate entries. If the same site has three saved logins, you probably only need one. Clean it up.
- Weak or reused passwords. Most password managers have a built-in security dashboard (1Password calls it Watchtower, Bitwarden has a Vault Health Reports section, LastPass uses a Security Dashboard). Pull it up and actually read what it says. If you've been ignoring those red flags, today's the day.
Check What Else Is Sitting in There
Passwords are just the beginning. Over time, password managers accumulate a surprising amount of sensitive data beyond login credentials.
Payment methods. Many people save credit and debit card numbers inside their password manager for autofill. Go to your stored cards section and ask yourself: are all of these still active? Do you actually need them saved here? If a card was compromised and replaced, that old number might still be sitting in your vault.
Personal info and identities. Autofill profiles — the ones that fill in your name, address, phone number, and email on web forms — are often set up once and forgotten. Check if your address is current, your phone number is accurate, and that you're not still saving an old email address you no longer control.
Secure notes. This is where things get interesting. A lot of people use the secure notes feature to stash all kinds of sensitive stuff: Social Security numbers, passport info, Wi-Fi passwords, recovery codes, even answers to security questions. Scroll through these and ask whether each one needs to be there — and whether it's accurate.
Look at the Metadata Your Manager Is Collecting
Here's the part most people never think about: your password manager isn't just storing what you put in — it's also logging data about how you use it.
Depending on the app, that can include:
- Login history and timestamps — when you accessed the vault, from which device
- Browser extension activity — which sites you visited that triggered autofill
- Device information — what hardware and software you're running
To see what's being tracked, head into your account settings on the web dashboard (not just the app). Look for sections labeled "Activity Log," "Login History," or "Connected Devices." In 1Password, this is under your profile on 1Password.com. In Bitwarden, check the web vault under Settings. LastPass users can find device history under Account Settings.
If you see devices listed that you don't recognize or no longer use, remove them. That's a dangling access point you don't need.
Review Your Emergency Access and Sharing Settings
Some password managers let you grant emergency access to another person — a spouse, family member, or trusted contact. That's a great feature, but only if it's set up intentionally.
Check whether you have any emergency access contacts enabled and confirm those are people you still want to have that access. Same goes for any shared vaults or shared folders. If you set up a shared login with a former roommate or an ex and never cleaned it up, now's the time.
Think About Whether Your Manager's Privacy Policy Works for You
This part requires a little homework, but it's worth it. Pull up the privacy policy for your password manager and look for answers to these questions:
- Does the company use zero-knowledge encryption? (They should — this means even they can't read your data.)
- Is the app open source? Open-source code can be independently audited, which is a meaningful trust signal. Bitwarden is a strong example here.
- Where are your vaults stored, and under which country's laws?
- Has the company had any notable security incidents?
If you're using a lesser-known or free password manager that came bundled with something else, it's worth doing a quick search on its reputation. Not all password managers are created equal.
When to Consider Switching
You don't need to switch password managers just because you did an audit. But here are some signs it might be worth considering:
- The app doesn't offer zero-knowledge encryption
- There's no clear audit log or device management
- The company has had a breach and hasn't been transparent about it
- You're on a free plan with a provider that monetizes user data
Bitwarden is a solid free option with open-source code. 1Password and Dashlane are well-regarded paid options with strong privacy track records.
The Takeaway
Your password manager is only as secure as the attention you give it. A quick audit every few months — clearing out old entries, reviewing saved payment info, checking connected devices, and skimming the privacy settings — keeps that trust well-earned. Think of it less like a locked vault and more like a filing cabinet that occasionally needs a good clean-out.
Set a reminder. Do it now, actually. It takes less time than you think.