We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Password manager review · checked July 14, 2026

Is Avast Password Manager Safe in 2026? Honest Review

The current Avast Password Manager is a supported standalone extension and mobile app—not the retired Avast Passwords product. Its AES-256, client-side encryption, separate vault password and recovery key are credible foundations. We still rank it below the category leaders because Avast publishes too little cryptographic detail, no current independent product audit, and no documented passkey, TOTP, family-vault or emergency-access system.

6.7/10 current product Old Avast Passwords retired AES-256 vendor claim No borrowed crowd score

Quick verdict: Avast Password Manager is a reasonable basic vault for someone already comfortable with Avast, provided they use the new standalone product, create a unique vault password, save the recovery key offline and enable Avast Account 2FA. We found no current evidence that the new vault is broadly compromised. We would still start with 1Password, Bitwarden, Proton Pass or KeePassXC: they offer stronger public assurance, portability, platform reach or family/recovery workflows. Legacy Avast Passwords users who missed the May 2025 migration deadline need official support, not another obsolete installer.

Legacy password vault migrating to a current encrypted vault with recovery key and two-factor protection
The current standalone vault has a different recovery and security model from the retired Avast Passwords app.
Editorial score6.7/10
Encryption claimAES-256
PlatformsWeb + mobile
Best fitBasic personal use
What the current product gets right
  • Client-side AES-256 encryption and vendor-described zero-knowledge design
  • Separate Avast Account and vault-password layers with optional account 2FA
  • Recovery key plus biometric vault-password reset on an enrolled phone
  • Logins, cards, bank accounts, addresses and secure notes with cross-device sync
  • CSV import/export and current Android, iOS, Chrome, Firefox and Edge support
Why it trails our leaders
  • No current public independent audit of the standalone password-manager clients/protocol
  • No Linux desktop experience and no Safari extension for the new product
  • No documented passkey, TOTP, attachment, emergency-access or mature family-vault workflow
  • Current price/renewal isn't clearly published on a dedicated public US product page
  • Avast's Jumpshot privacy history raises a trust burden the current documentation only partly answers

First, identify which Avast password manager you have

Search results use “Avast Passwords” and “Avast Password Manager” as though they're one continuous app. They aren't. Avast stopped selling new licenses for the original Passwords product in 2020, later ended support across Windows, macOS, Android and iOS, and built a new standalone browser extension and mobile application.

The final Avast Passwords migration FAQ said legacy cloud data would be kept only until the end of May 2025. It warned Windows users that cloud-synced and locally stored old data would stop being accessible after that point; Mac and mobile data might remain locally available but should still be migrated. That deadline passed more than a year before this review.

The current product is active. Avast's support center documents the new browser extension and mobile apps, and Google Play shows the Android app updated on June 15, 2026. A temporary extension problem or an old Avast Passwords icon disappearing doesn't prove the current standalone manager is discontinued.

QuestionLegacy Avast PasswordsCurrent Avast Password Manager
StatusSupport ended; data-retention/migration deadline was May 2025Supported standalone extension and mobile app
Desktop formComponent tied to older Avast Antivirus/Mac appChrome, Firefox and Edge extension plus web app
MobileRetired Avast Passwords appsCurrent Android and iOS apps
RecoveryOld master-password/sync modelVault password, downloadable recovery key and mobile biometric reset
What to doPreserve any accessible copy and contact official support; don't reinstall from third partiesEvaluate, set up recovery, import a sample and test export before committing

The distinction also changes vulnerability history. CVE-2020-15024 described the old Avast Antivirus password-manager component retaining an entered password in Windows memory after logout or Lock Vault. That's relevant to legacy cleanup and password rotation; it doesn't prove that the separately built current extension has the same flaw.

Avast Password Manager at a glance

Current productStandalone browser extension/web app for Windows and macOS; mobile app for Android and iOS
Supported browsersLatest three versions of Chrome, Firefox and Edge; current install help says no Safari extension
Mobile minimumsAndroid 8+ and iOS 13+ in the current security help
Vault claimAES-256, encrypted on-device before cloud storage, decrypted with the vault password
Account protectionOptional two-factor authentication on the Avast Account
RecoveryPrintable recovery key; enrolled mobile app can reset with biometric authentication
Stored dataLogins, cards, bank accounts, addresses and notes; password generator and autofill
Premium featuresPassword Guardian health/leak monitoring and One-Touch Login
Portable exitBrowser/web-app export to readable CSV
Independent assurance gapNo current public third-party audit report found for the standalone manager/protocol

Our 6.7/10 score is for the current standalone Avast Password Manager, not the retired product. The foundation is credible enough for basic personal use, but the public evidence isn't detailed enough for a top recommendation. An AES name and a “zero-knowledge” label don't replace protocol documentation, audit artifacts, recovery analysis and a mature feature set.

This isn't an antivirus review. Avast's 2026 malware-detection scores don't test password-vault encryption, browser form matching, recovery-key handling or CSV export. The old version of this article and many competitor pages blur those categories; we don't.

Is Avast Password Manager encrypted and zero knowledge?

Avast's current password-manager security guide says vault data is encrypted on the device with AES-256 before it enters cloud storage. The vendor says the vault password is never stored or sent to its server, only encrypted data is stored there, and decryption occurs on the user's devices.

Avast also describes a challenge mechanism: a client must prove successful entry of the vault password before encrypted vault data is transferred from the server. Account sign-in can use Avast Account 2FA, and automated account guessing is slowed with CAPTCHA and rate-limiting measures. Those are useful layers: compromising an account password alone shouldn't be equivalent to learning the separate vault password.

“AES-256” answers only one question. Avast's public consumer help doesn't expose the current key-derivation function and work factor, salt format, authenticated-encryption mode, per-item metadata exposure, device authorization protocol, recovery-key wrapping, server-state authentication or malicious-server threat model. We also didn't find a current downloadable independent audit of the new standalone extension, mobile apps and backend protocol.

That evidence gap doesn't prove a hidden backdoor. It limits what an outside reviewer can verify. A zero-knowledge marketing claim is strongest when a current design document and third-party assessment show how every recovery, sharing, synchronization and legacy-compatibility path preserves it.

Endpoint risk remains. When the vault is unlocked, credentials must exist in usable form in memory or form fields. Infostealers, hostile accessibility services, a malicious extension, screen capture, clipboard monitoring or a phish that imitates the Avast unlock flow can bypass strong at-rest encryption. Keep the operating system, browser and extension current, and restrict extension access if that doesn't break your required workflow.

Security conclusion: the current vendor-described design is materially safer than password reuse or a plaintext spreadsheet. It isn't publicly documented or independently audited at the level we expect from the strongest dedicated competitors.

Recovery is better than the old product—if you prepare it

During desktop setup, Avast asks the user to download a recovery key. Its current guide recommends printing the key, keeping the physical copy safe and deleting the digital file. The recovery key can reset a forgotten vault password; without it, a desktop-only user may be unable to decrypt the vault.

An enrolled Android or iOS app provides another route. Avast says the mobile app can use biometric authentication and device secure hardware to reset the vault password. The browser extension can't perform that biometric reset. This is useful recovery, but it makes phone security part of the vault threat model: protect the device with a strong passcode, current OS, remote lock/wipe and carefully enrolled biometrics.

Avast Account recovery and vault recovery are separate. Email or social sign-in can restore account access, but the separate vault password/recovery material controls encrypted secrets. Use different passwords for the primary email, Avast Account and vault; protect the email and Avast Account with strong 2FA because they control device enrollment, subscription and recovery flows.

If neither recovery key nor enrolled biometric reset is available, the documented alternative is to reset/delete the vault, which permanently removes its data. That isn't a secret vendor decryption path. Test the recovery key on a spare profile/device before filling the vault, and store an offline note that identifies which account and product the key belongs to.

One-Touch Login is a paid convenience feature that approves desktop unlock from a phone. Treat it as device authorization, not as permission to weaken the phone passcode or vault password. Deny unexpected prompts and investigate them; repeated approvals can train users to authorize an attack.

Features: solid basics, visible power-user gaps

The current vault stores website/app logins, credit and debit cards, bank-account data, postal addresses and secure notes. Records can carry additional fields and tags. Users can mark sensitive records to require the full vault password before display, a good control on an already unlocked device.

Browser and mobile clients can save new logins, generate passwords, autofill credentials and synchronize through the encrypted cloud vault. Mobile settings include biometric or PIN unlock, auto-lock, clipboard clearing and the ability to disable screenshots. Keep screenshots disabled and choose the shortest practical auto-lock and clipboard-clearing intervals.

Password Guardian is Premium-only. It grades stored credentials and identifies weak, duplicated, old and leaked passwords. Avast's current product policy says potential leak monitoring uses SpyCloud's stolen-account repository. A match is a response signal, not proof that Avast caused the exposure: change the password on the real site, revoke sessions, inspect recovery settings and enable phishing-resistant MFA.

Current support doesn't document passkey storage, TOTP authenticator codes, file attachments, emergency access, shared family vaults or a business administration model. Search didn't find reliable current how-to material for those capabilities. Don't assume a logo in an antivirus account means every modern password-manager feature exists.

Family Sharing in an Avast Account is documented as subscription sharing with up to five people. It isn't documentation for a 1Password-style family vault with separate private spaces, granular shared vaults and organizer recovery. Give every person a separate Avast Account and vault unless current official support explicitly confirms a different safe design for your plan; never share one vault password through a family invitation.

The lack of documented passkeys is increasingly important. Passkeys can remove reusable site passwords and resist phishing on supported services. If you already store passkeys in another manager, don't migrate until Avast documents creation, cross-device sync, export and recovery for them.

Platforms, browsers and daily use

Desktop users install a browser extension on Windows or macOS. Current official installation help covers Chrome, Firefox and Edge and explicitly says the standalone extension is unavailable in Safari on Mac. The new product isn't a conventional native desktop client and has no documented Linux package.

Mobile apps support Android and iOS; the current security guide lists Android 8+ and iOS 13+. Store availability can vary by country and device. The Google Play listing showed a June 15, 2026 update on our audit date, evidence that the Android app is active—not proof that every platform has identical features or release cadence.

The basic workflow is straightforward: sign into an Avast Account, create a separate vault password, save the recovery key, install only the official extension/app, import a few records and enable autofill. The current web app adds wallet and address fields that weren't part of every legacy Avast Passwords workflow.

Autofill is safe only when the origin match is correct. Prefer click-to-fill over filling immediately on page load, especially for cards and personal data. If Avast refuses to fill a familiar site, verify the full domain and TLS connection rather than copying the credential into a lookalike page.

Current community reports are mixed: some users describe working cross-device basics, while others report extension availability or family-account confusion. These are directional test cases, not prevalence data. Before importing the full collection, test the exact OS/browser combination, mobile autofill, sign-in after a restart, offline behavior, recovery and CSV export.

Privacy and the Avast trust question

The current Avast Products Policy distinguishes encrypted vault content from service and device telemetry. It says usernames, passwords, cards, notes and connected URLs stored by the user are encrypted and retained while the account is active. Avast says it can't decrypt the legacy Passwords content; current security help makes the equivalent zero-knowledge claim for the new manager.

The policy also lists unencrypted operational data: feature use, counts, leak-check activity and errors for service provision and product improvement; information about interaction with web pages to improve recognition of login/password-change forms, with 60 days of raw data stated; and device/browser/extension version plus city/country-level location and identifiers under stated 24- or 39-month purposes.

That's more transparent than saying “we collect nothing,” but readers should decide whether the telemetry surface fits a vault extension. A password manager legitimately needs to recognize login fields; that doesn't make every retention period or product-improvement purpose unavoidable. Use available privacy controls and request clarification for any ambiguous field before placing especially sensitive identities in the wallet.

Avast also carries a serious historical trust cost. The US Federal Trade Commission's Avast case alleged that browsing data collected through Avast products from 2014–2020 was sold through Jumpshot without adequate notice/consent and could be re-identified. The final order bans Avast from selling/licensing Avast-product browsing data for advertising, requires data/model deletion and imposed $16.5 million in redress.

Jumpshot was a browsing-data/privacy failure, not evidence that current encrypted password-vault contents were sold or decrypted. We keep that boundary explicit. It still matters because a password-manager vendor asks for durable organizational trust, and browser extensions operate beside every login. The correct response is neither “Avast can read every current password” nor “the past is irrelevant.”

Migration, imports and the plaintext CSV problem

Current Avast Password Manager can import saved logins from its own CSV and from several browsers/managers. Official help includes legacy Avast Passwords, Chrome, Edge, Firefox, 1Password, Bitwarden, Dashlane, LastPass, True Key and Norton formats. The exact list and required steps vary, so follow the current source-specific page rather than manually changing column names first.

Export is available from the browser extension's web app under Settings → My data → Export my vault data. Avast confirms the result is CSV and tells users to keep it securely or delete it. A CSV that another manager can read is a plaintext credential dump, not an encrypted backup.

Export on a trusted full-disk-encrypted device, outside cloud-sync folders. Import immediately, verify row and category counts, then remove the CSV from Downloads, trash, backups, cloud version history and any editor's autosave/recovery location. If it must exist temporarily, place it inside a strongly encrypted container and delete the unencrypted original.

CSV is usually login-centric. Wallet entries, bank accounts, addresses, notes, tags, custom fields, passkeys, TOTP seeds and attachments may not map to the destination even when the import says “complete.” Build a category/count checklist without recording secrets, and inspect representative records manually.

If the only remaining data is inside legacy Avast Passwords and was never exported before the May 2025 deadline, don't download old installers or send a vault file to a forum helper. Preserve any still-unlocked device, disconnect unnecessary cleanup/sync operations and contact official Avast support. Avast's retention notice means recovery may no longer be possible; no honest guide can promise otherwise.

Free versus Premium: useful split, unclear public price

Avast's migration FAQ describes the current Password Manager as available in free and paid forms. The paid subscription adds Password Guardian and One-Touch Login. Core vault storage, synchronization, entry types, import and recovery are presented as base functionality in current support.

We didn't find a stable dedicated US public price page for Avast Password Manager on July 14, 2026. Avast's general store emphasizes antivirus, VPN, cleanup and other modules; app/account offers can depend on region and existing subscription. We won't revive the old page's fabricated/currently obsolete $19.99 figure or convert an unverified monthly app amount into an annual claim.

Before paying, capture the annual total, number of users/devices, trial end, auto-renewal state, next-term price, refund window and whether Password Manager is a standalone entitlement or included module. Avast's broader subscriptions are continuous subscriptions and renew at the then-current published price, so “per month” marketing should be read alongside the charged term.

Premium is worthwhile only if Password Guardian or One-Touch materially improves your workflow. Weak/duplicate/leak monitoring is helpful, but Bitwarden and Proton Pass offer strong free competition; a paid family should compare 1Password's mature household features. Price can't compensate for a missing required platform or record type.

Avast Password Manager versus better-known alternatives

ProductBest fitAdvantage over AvastTrade-off
1PasswordPaid households and polished cross-platform usePublic assessments, Secret Key, mature family vaults/recovery and broader feature depthNo permanent free plan
BitwardenStrong free tier, Linux and open-source preferenceBroad platforms, unlimited basics, public code/audits, TOTP/passkeys and portable exports2026 malicious-server research creates its own design questions
Proton PassPrivacy, aliases and modern free useOpen clients, public audits, passkeys/TOTP and email aliasesYounger product and ecosystem dependence
KeePassXCTechnical users wanting local controlLocal portable KDBX database, Linux and no mandatory vendor accountYou own sync, backups, mobile client and recovery
AvastExisting Avast user needing a simple personal vaultFamiliar account, base free tier, recovery key/mobile reset and rich basic recordsThin public assurance and power-user/family gaps

Avast is defensible when its basic record model, three desktop browsers and mobile apps match your needs and you value one vendor account. It's a weak reason to move a healthy vault from a more mature competitor.

Our Avast Secure Browser review covers a different built-in browser password store and Avast's browser privacy surface. A browser's local password feature, the current standalone Password Manager and retired Avast Passwords shouldn't be combined into one verdict.

How to set up Avast Password Manager safely

  1. Install the current official product. Use Avast's support links to the Chrome, Firefox or Edge store or the official Android/iOS listing; reject archived Avast Passwords installers.
  2. Separate all three credentials. Give the primary email, Avast Account and vault different long passwords, then enable strong 2FA on the email and Avast Account.
  3. Print and protect the recovery key. Store the paper copy in a locked physical location, label the account/product without writing the vault password, and delete the downloaded key file.
  4. Harden local unlock. Use a strong device passcode, carefully enrolled biometrics, short auto-lock, clipboard clearing and disabled screenshots; deny unexpected One-Touch prompts.
  5. Import a representative sample. Test logins, notes, wallet/address data, international characters and multiple usernames before moving the full vault.
  6. Verify autofill by origin. Prefer deliberate click-to-fill, inspect the complete domain and keep sensitive records set to require the vault password.
  7. Run recovery and exit drills. Unlock another supported device, verify the printed recovery key and create a test CSV export before depending on the service.
  8. Remove migration residue. Reconcile category counts, delete every plaintext CSV copy and rotate high-value credentials if an export entered cloud sync, email or an untrusted device.

Avast Password Manager FAQ

Is Avast Password Manager safe in 2026?

The current standalone product has a credible vendor-described foundation: client-side AES-256 encryption, a vault password not sent to the server, encrypted cloud storage, account 2FA, a recovery key and brute-force controls. We found no evidence of a broad current vault compromise. It still lacks a public current independent product audit and several features offered by category leaders.

Was Avast Passwords discontinued?

Yes. The old Avast Passwords product ended support across Windows, macOS, Android and iOS, and Avast said legacy data would be kept only through May 2025. The current Avast Password Manager is a separate supported extension/mobile app. Don't install the old product from an archive.

Can Avast read my passwords?

Avast says the current manager encrypts data on your device before upload, doesn't store or transmit the vault password, stores only encrypted vault data and can't view it. That's a zero-knowledge claim, but Avast hasn't published enough protocol detail or a current independent audit for us to verify every server, recovery and client scenario.

What happens if I forget the Avast vault password?

Use the recovery key saved during setup, or reset from an enrolled Android/iOS device with biometric authentication. The browser extension alone can't perform the biometric reset. Without recovery material or an enrolled device, resetting the vault permanently deletes its contents. Avast Account password recovery doesn't decrypt the separate vault.

Does Avast Password Manager support passkeys or authenticator codes?

Current official feature and support pages we reviewed don't document passkey storage/sync/export or TOTP authenticator-code storage. Don't assume support. If either is required, test with noncritical accounts or choose a manager that publishes current passkey and TOTP workflows.

Is Avast Password Manager free?

Avast documents free and paid versions. Premium adds Password Guardian and One-Touch Login. A stable dedicated public US price wasn't available in our July 14, 2026 research, so verify the annual total, trial, renewal price, region and entitlement in the current account/store rather than relying on the old $19.99 article claim.

Can I export Avast passwords?

The current web app exports vault data as CSV from Settings → My data. CSV is a readable credential file, not an encrypted vault. Export on a trusted encrypted device, import promptly, verify every record category and remove copies from Downloads, trash, backups, sync history and editor autosaves.

What is the best Avast Password Manager alternative?

Bitwarden is our broadly useful free/open-source choice, 1Password is the paid family pick, Proton Pass suits privacy and alias users, and KeePassXC suits local-control users. Choose by platforms, passkeys/TOTP, sharing, recovery, public audits and export—not by antivirus malware-test scores.

Final verdict: safe enough for basics, not our first recommendation

The current Avast Password Manager earns 6.7/10. It has the essential bones of a competent personal vault: on-device AES-256 encryption, separate account/vault credentials, encrypted sync, a thoughtful recovery key, mobile biometric reset, current apps, basic rich records and a portable CSV exit.

The public assurance and feature story is thinner than the best alternatives. Avast doesn't publish a current independent audit of the standalone manager, its consumer security page omits important cryptographic parameters, and current help doesn't establish passkeys, TOTP, Linux, Safari, emergency access or mature family sharing. Pricing is also unnecessarily hard to verify publicly.

Avast's Jumpshot history doesn't mean it can decrypt the current vault, but it justifiably raises the evidence bar. The current Products Policy is specific about encrypted content and operational telemetry; a public product audit and deeper design paper would do more to rebuild trust.

Keep Avast if you already use the current product, understand recovery, have verified export and need only its basic personal workflow. New users should compare Bitwarden, 1Password, Proton Pass and KeePassXC first. Legacy Avast Passwords users should stop treating the retired app as a supported vault and preserve any remaining accessible data with official help.