We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Password manager review · checked July 14, 2026

Kaspersky Password Manager Review 2026: Capable Vault, Hard Regional Limits

Kaspersky Password Manager covers encrypted sync, autofill, documents, TOTP codes and passkeys, but the buying decision starts with location. We don't recommend deploying it in the United States because sales and codebase updates are unavailable there. Elsewhere, it's most defensible as a Kaspersky Plus or Premium inclusion—not as a reason to leave a stronger dedicated password manager.

6.4/10 outside restricted regions Not recommended in the US Passkeys and TOTP included No borrowed crowd score

Quick verdict: Kaspersky Password Manager is usable for an existing Kaspersky Plus/Premium customer in a supported region who wants a simple personal vault on Windows, macOS, Android and iOS. Its core is stronger than this page's old 2019 version suggested: current clients support passkeys, password health, documents, browser autofill and cross-device sync. We would still choose 1Password, Bitwarden, Proton Pass or KeePassXC first. They offer clearer portability, family/recovery choices, public scrutiny or local control. US users should migrate rather than look for a workaround.

Password vault on a laptop and phone with passkeys, recovery key and United States availability warning
Vault design is only half the decision: updates, export, recovery and regional availability determine whether the product is safe to depend on.
Editorial score6.4/10
US verdictDon't deploy
Free tierVery limited
Best fitExisting bundle
What it gets right
  • AES-encrypted personal vault with a main password Kaspersky says it doesn't store
  • Windows, macOS, Android and iOS apps with automatic sync
  • Passkeys, TOTP authenticator, password health and password generator
  • Logins, cards, addresses, notes, documents and images in one vault
  • Useful when Premium access is already included with Kaspersky Plus or Premium
Why it trails our leaders
  • No dependable US update path and other region-specific availability limits
  • Official pages conflict on whether the current free cap is five or 15 entries
  • No Linux client and no clearly documented family sharing or emergency access system
  • Generic imports cover only web-account fields; export can be an unencrypted TXT file
  • No current product-specific public cryptographic audit with enough detail to close key trust questions

Kaspersky Password Manager at a glance

Current purposePersonal password, passkey, document, card, address and note vault with browser/mobile autofill
PlatformsWindows 10/11, current macOS, Android and iOS/iPadOS; no Linux password-manager client
Browser/passkey supportCurrent Windows help lists Chromium Edge, Chrome, Firefox, Brave, Vivaldi, Opera/Opera GX, Yandex Browser and Comodo Dragon for passkeys
Storage modelEncrypted local vault synchronized through My Kaspersky; online vault management is available
Main password recoveryNo recovery of a forgotten main password; a new vault means losing access to the old encrypted data
Free planOfficial pages disagree by region/version: current support documents 15 active entries, while a current Latin American product page says five
Trial and renewalOfficial global/UK pages showed a 15-day trial; paid term starts automatically unless cancelled and renewal price can change
US availabilityDon't buy or deploy: sales and codebase updates are unavailable under the US Commerce Department determination

Our 6.4/10 score evaluates the current product where it's legally sold and updated. It isn't a universal score: in the United States, the update boundary overrides the feature list, so our verdict is “do not deploy.” We don't average those two decisions into a misleading global star rating.

This is also a password-manager review, not a transfer of Kaspersky antivirus lab results. Strong malware-detection results for the company's security suite don't validate the vault protocol, import behavior, recovery model or passkey portability.

US ban and regional availability: check this before security features

On June 20, 2024, the US Department of Commerce's Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from providing covered cybersecurity and antivirus products or services to US persons. BIS allowed existing codebase and signature updates only until September 29, 2024. The agency says consumers who keep existing products don't face legal penalties, but assume the associated security risk.

Kaspersky disputes the basis of the decision. In its July 18, 2024 compliance statement, it said sales had stopped and US operations would wind down, while arguing that the decision was geopolitical rather than a product-integrity finding. We preserve both positions. For a password vault, however, the practical fact is simpler: a client without a dependable code-update path isn't a sensible new dependency.

Kaspersky's own current Windows help says update functionality, including codebase updates, may be unavailable in the United States. Its January 2026 regional-restrictions page also says downloads and some features are unavailable in the US and its territories. Using a VPN, foreign storefront or old installer doesn't restore supported updates or change who the transaction serves.

US recommendation: don't install a new Kaspersky Password Manager vault and don't move passkeys into it. Existing users should export from the latest client they can safely access, verify the destination, rotate high-value credentials and remove plaintext export files. Keep the old vault only long enough to confirm the migration.
Location/situationWhat current sources sayOur recommendation
United States / US personCovered Kaspersky cybersecurity transactions and codebase updates are prohibited; Kaspersky has stopped US salesDon't deploy; migrate to a currently supported alternative
Poland or Ukraine on Apple platformsKaspersky says Password Manager may be unavailable from the App StoreConfirm install and update availability on every device before committing
Other supported regionGlobal and regional sites continue to offer the product, trial and current appsEvaluate features, renewal, export and local law; don't assume another region's plan terms
Travel or relocationAccount region and storefront can affect subscription use, downloads and featuresTest the least-supported destination and keep a portable export/recovery plan

Encryption and security architecture

Kaspersky describes the vault as an encrypted file. Its technical help says vault data uses an AES-based symmetric scheme and derives the key from the main password with PBKDF2. The company says it doesn't store the main password on devices or in cloud storage, so employees can't simply send a reset link that decrypts the existing vault.

That no-recovery boundary is a real security property, but “AES” and “PBKDF2” aren't a complete threat model. The public help page we found doesn't expose enough current parameters—iteration count, salt handling, authenticated-encryption construction, key hierarchy, device authorization, server-state authentication or independent test artifacts—to compare the design as precisely as 1Password's design paper or an open KeePass-compatible database. We found broad company transparency and audit material, but not a current, product-specific public cryptographic assessment of Kaspersky Password Manager.

My Kaspersky remains part of the system. The account connects devices and syncs the encrypted vault; the main password unlocks vault contents. Treat these as two separate credentials. Protect the account with its available SMS plus authenticator-app two-step verification and a password not reused as the vault password. A compromised account or session can still affect device enrollment, subscription, synchronization and deletion even if it doesn't reveal the main password directly.

Local endpoint security remains decisive. Once the vault is unlocked, malware with sufficient access, a hostile browser extension or a fake overlay can steal data as it is viewed or autofilled. Biometric unlock is convenience backed by a device-protected key; it isn't a second independent factor for every saved website.

What we can say: the current design is materially better than storing passwords in a document or reusing them. What we can't certify: that marketing phrases such as “only you can access it” cover every malicious-server, compromised-device, recovery and synchronization scenario.

The old predictable-password flaw: fixed, but old passwords stay old

Kaspersky Password Manager has one unusually relevant historical failure. NVD's CVE-2020-27020 record says the password generator wasn't completely cryptographically strong and could produce predictable passwords when an attacker knew additional information such as generation time. NVD scores it 7.5 High.

The affected versions aren't current: Windows before 9.2 Patch F, Android before 9.2.14.872 and iOS before 9.2.14.31. Current supported clients are beyond those builds, so it would be wrong to describe the present generator as still vulnerable on that evidence. It would also be wrong to pretend the patch silently changed credentials already generated by an old client.

If you used Kaspersky Password Manager's generator in an affected version, rotate high-impact credentials: primary email, financial accounts, cloud storage, mobile carrier, domain registrar, government/identity portals and any account whose creation time may be observable. The old flaw doesn't mean every historic password was cracked; rotation removes a preventable residual risk.

The broader editorial lesson is useful: a strong vault can still generate weak secrets, and a fixed generator can't repair secrets copied to websites years earlier. Product update history belongs in a password-manager review even when the CVE is no longer exploitable in the current client.

Features, passkeys and supported platforms

Current Kaspersky Password Manager stores website and application logins, bank cards, addresses, text notes, documents and images. The browser extension saves and fills logins, cards and addresses. Password Health identifies weak or reused passwords, while the data-leak connection in the broader suite can flag exposed accounts. Desktop and mobile biometric unlock reduce the temptation to leave the vault open.

Passkeys are now a serious feature, not a roadmap promise. Kaspersky's current Windows passkey guide lists recent Chromium-based Edge, Chrome, Firefox, Brave, Vivaldi, Opera, Opera GX, Yandex Browser and Comodo Dragon. It warns that passkeys aren't supported on Windows 7, 8 or 8.1 and tells users to retain an alternative login method before deleting one.

The current product line covers Windows, macOS, Android, iOS and iPadOS. It has no Linux password-manager app even though Kaspersky's wider Premium security suite now lists some Linux support. Don't confuse suite platform coverage with the vault's clients. Browser availability and passkey support also differ by operating system, so test the exact phone/browser/desktop combination.

The in-app authenticator can generate TOTP codes. Keeping password and TOTP in one vault is convenient and still better than skipping two-factor authentication, but it reduces factor separation. Use a hardware security key or a separate authenticator for the vault account, primary email, financial services and other reset authorities.

What is missing matters. We didn't find a documented consumer family system with separate private member vaults, granular shared vaults and administrator recovery comparable with 1Password Families or Bitwarden Families. We also didn't find a mature emergency-access/digital-legacy workflow. A multi-device license isn't the same as safe multi-person sharing; never give relatives one common main password.

Free, paid and bundled plans

The current global and UK pages presented a 15-day trial on the audit date. Unless cancelled during the trial, a paid subscription starts and auto-renews. Kaspersky says renewal can differ from the introductory price and that the next renewal price is sent by email. The checkout is dynamic and region-specific, so we don't publish a fabricated universal dollar amount.

The product is sold separately in some regions and Premium access is included with Kaspersky Plus and Premium. That bundle is its best economic case: if a supported-region customer already pays for the suite, the incremental price can be effectively zero. It still doesn't erase switching cost or justify moving from a well-established vault that already works.

The free tier isn't competitive for a real password collection. Worse, official pages disagree. Current iOS support documents up to 15 active entries, while the current Latin American product page states five. This may reflect a regional or rollout difference. We won't resolve the contradiction by guessing: check the exact local app/checkout before import.

When paid access ends, excess records can become inactive/read-only and cloud handling changes. Kaspersky advises downloading images and PDFs before downgrading because inactive documents may be deleted from cloud storage. That's an important exit condition, not a footnote.

Before accepting a trial: record the first charge date, term length, renewal method, included devices, local free-entry cap and what happens to documents after expiry. Cancel auto-renewal immediately if the trial is only for evaluation; access continues through the paid/trial period.

Import, export and recovery: the weak side of the workflow

Kaspersky's Windows importer handles current Chrome, Firefox, Chromium Edge and Yandex Browser stores. It also lists direct imports from LastPass, KeePass, Dashlane, 1Password and Norton Identity Safe 2014. A generic UTF-8 CSV path is available, but its documented schema imports web accounts only: URL is required, with optional username, password and name fields.

That narrow schema explains current complaints about moving from Bitwarden or Proton Pass. A custom CSV can move ordinary website credentials after field mapping, but secure notes, cards, identities, attachments, TOTP seeds, passkeys, custom fields and folder structure may not transfer. Count item types—not just rows—before deleting the source vault.

Exit is more concerning. Kaspersky's current import/export guide says Windows and My Kaspersky can export credentials and notes to a TXT file and explicitly warns that the file isn't protected. A proprietary vault backup is useful for restoring within Kaspersky, but it isn't a neutral migration format.

A plaintext TXT export is temporarily acceptable when the alternative is permanent lock-in, but handle it as a complete breach waiting to happen: export on a trusted device, import directly, verify, then remove it from Downloads, recent-file lists, sync folders, backups and trash. Full-disk encryption reduces lost-device risk but doesn't protect a file while the user session is open or after cloud synchronization.

There's no main-password recovery for the encrypted vault. Create a long unique passphrase, store an offline recovery note that identifies the account and doesn't sit in the same vault, and test access on a second device. If you forget the main password, the supported answer is a new vault—not a secret vendor backdoor.

Daily-use strengths and missing features

The basic flow is sensible: create or import a login, let the extension match the saved origin, unlock when needed and keep the vault synchronized. Kaspersky also stores application credentials on desktop, which browser-only tools can neglect. Categories for cards, addresses and documents keep a personal vault understandable without custom database design.

The interface is attractive to someone already in My Kaspersky, and the separate app avoids burying the vault inside antivirus settings. Password Health and the generator solve the highest-probability problem—reused credentials—while passkeys provide a path away from shared secrets on supported sites.

Power-user and household gaps remain. There's no Linux app, generic import is lossy, portable encrypted export is weak, secure sharing is sparse and family recovery isn't a headline consumer capability. We also want clearer public documentation for passkey export, device authorization and exactly what happens when a server account is compromised.

Autofill deserves a cautious setting. Let the extension suggest credentials after a deliberate click rather than automatically injecting personal or card data into every matching page. If the manager refuses to fill a familiar login, inspect the domain instead of copying the secret into a page that may be a phish.

This review doesn't invent scan times, CPU percentages or a “we cracked the vault” laboratory claim. We evaluated the recovered page, current official clients/documentation, public vulnerability record, plan flow, regional rules and migration surface. A full cryptographic assurance claim would require a published audit or reproducible client/server analysis beyond what Kaspersky exposes publicly.

Privacy, jurisdiction and the trust decision

A password manager necessarily asks for exceptional trust: client updates can see secrets after unlock, browser extensions operate near login forms, and cloud synchronization controls encrypted state. End-to-end encryption reduces server exposure but doesn't make vendor governance, update signing or jurisdiction irrelevant.

The US government says Kaspersky's Russia nexus and the government's capacity to influence its operations create an unacceptable national-security risk. Kaspersky rejects that conclusion and points to transparency centers, third-party audits and its Global Transparency Initiative. Readers should distinguish the government's risk determination from evidence that every Kaspersky employee can read every current password vault; the latter isn't what BIS demonstrated.

Our practical decision doesn't require resolving every geopolitical dispute. In the US, the update and sales prohibition is enough to rule the product out. Elsewhere, individuals should consider local law, employer policy, data sensitivity, vendor concentration and whether an alternative offers the same daily value with fewer procurement or continuity questions.

We also avoid a false opposite: choosing a US- or EU-based vendor doesn't make a vault automatically safe. 1Password, Bitwarden, Dashlane, LastPass and other services have disclosed design limitations, incidents or vulnerabilities. Prefer verifiable architecture, current updates, useful export and a failure model you understand.

Kaspersky Password Manager versus better alternatives

ProductChoose it whenAdvantage over KasperskyTrade-off
1PasswordYou want the best paid household experienceSeparate Secret Key, mature family vault/recovery model, broad platform supportNo permanent free plan
BitwardenYou need a strong free tier or open sourceUnlimited free items/devices, Linux, clearer export and sharing ecosystem2026 malicious-server research creates its own design questions
Proton PassPrivacy and email aliases are centralGenerous unlimited-device free tier, open clients and aliasesYounger workflow and fewer years of maturity
KeePassXCYou want a local encrypted fileNo vendor account/cloud required, Linux support, portable KDBX databaseYou own backups, sync, mobile client choice and recovery
KasperskyYou already pay for Plus/Premium in a supported regionSimple bundle integration, documents, TOTP and current passkeysRegional restrictions, tiny free tier, weaker portability/family model

For a broader ranked decision, use our best password manager comparison. It separates free, paid, privacy, family and offline use instead of treating one universal score as the answer.

What current user reports add

Recent Kaspersky community threads repeatedly surface import limitations, especially from Bitwarden and Proton Pass, and confusion about whether a multi-device security subscription creates separate password-manager profiles. Those reports are directional, not proof that every import fails. The current official CSV schema and sparse family documentation explain why the friction is plausible.

Other users describe smooth autofill and synchronization. That also makes sense: ordinary URL/username/password records fit the product's strongest path. Satisfaction depends heavily on whether a vault contains only website logins or also passkeys, TOTP seeds, attachments, identities, custom fields and shared records.

We don't turn forum votes into prevalence or a crowd rating. Community evidence identifies workflows to test; official documentation and reproducible behavior decide the factual claim.

How to set up Kaspersky Password Manager safely—or leave it cleanly

  1. Confirm region and update support. Check the official regional restrictions and local storefront on every device. US users should choose a different provider rather than work around availability.
  2. Install only the current official client and extension. Avoid archived installers, search ads and third-party download sites. Confirm the extension publisher and exact browser compatibility.
  3. Separate account and vault credentials. Give My Kaspersky and the vault different long passwords, then enable strong two-step verification on the account.
  4. Test before bulk import. Import a small sample containing a login, note, card, TOTP, attachment and passkey. Identify which types don't survive before moving the full collection.
  5. Rotate secrets from affected old generators. If passwords came from pre-fixed CVE-2020-27020 clients, change high-value and time-observable accounts first.
  6. Protect plaintext migration files. Export on a trusted encrypted device, import immediately, verify counts, then remove TXT/CSV files from local storage, cloud sync, backups and trash.
  7. Create independent recovery material. Record the My Kaspersky account, main-password hint/recovery process and subscription details offline; never keep the only recovery copy inside the locked vault.
  8. Run a second-device and exit drill. Sign in, unlock and sync on another supported device, then confirm you can create a usable export before the trial/renewal date.

Kaspersky Password Manager FAQ

Is Kaspersky Password Manager safe in 2026?

In supported regions, the current version is a capable encrypted vault and the historic predictable-generator flaw is fixed. Safety isn't universal: we don't recommend it in the United States because sales and codebase updates are unavailable. Elsewhere, use the latest client, a unique main password, two-step verification and a tested export/recovery plan.

Can I use Kaspersky Password Manager in the United States?

Existing users aren't penalized merely for continuing to use Kaspersky products, but the US Commerce Department prohibits covered Kaspersky cybersecurity transactions and updates. Kaspersky has stopped US sales, and its support pages warn that downloads, features and codebase updates may be unavailable. Migrate to a currently supported provider rather than bypassing the restriction.

Is Kaspersky Password Manager free?

A free version exists in some regions, but it's too limited for most real vaults. Official pages currently conflict: one support page allows 15 active entries while a Latin American product page says five. Confirm the limit in your local app. The global/UK site also offered a 15-day paid trial with automatic conversion unless cancelled.

Does Kaspersky Password Manager support passkeys?

Yes. Current Windows documentation supports passkey creation/use through several recent Chromium browsers and Firefox. Passkeys aren't supported on Windows 7, 8 or 8.1. Test creation, sync, recovery and export on every target platform before placing irreplaceable passkeys in any provider.

Can Kaspersky recover a forgotten main password?

No. Kaspersky says it doesn't store or transmit the main password, so it can't decrypt the existing vault for you. A forgotten main password means creating a new vault and losing access to the old encrypted data unless you remember it. Keep recovery material offline and test a second device.

Was Kaspersky Password Manager's password generator vulnerable?

Older clients were affected by CVE-2020-27020, which could make generated passwords predictable when an attacker knew additional information such as generation time. The listed affected builds are obsolete and current clients are fixed. Passwords generated by affected versions don't repair themselves, so rotate high-value historic credentials.

Can I import from Bitwarden or Proton Pass?

Kaspersky's documented direct-import list doesn't include them, but a generic UTF-8 CSV can import ordinary web accounts when mapped to URL, username, password and name. That schema doesn't preserve every note, TOTP seed, attachment, passkey, identity, folder or custom field. Test a representative sample and compare item types after import.

What is the best Kaspersky Password Manager alternative?

Bitwarden is the best broadly useful free alternative, 1Password is our paid/family pick, Proton Pass is strong for privacy and email aliases, and KeePassXC gives technical users a local encrypted database. The best choice depends on region, family recovery, devices, export needs and whether you can manage local backups.

Final verdict: useful bundle feature, weak standalone recommendation

Outside restricted regions, Kaspersky Password Manager earns 6.4/10. It isn't obsolete: current apps cover the mainstream platforms, passkeys and TOTP have joined the expected vault features, and the main-password/no-recovery boundary is meaningful. Existing Kaspersky Plus or Premium users can get acceptable value without another subscription.

It still trails the category leaders. The free tier is tiny and inconsistently documented, Linux is absent, import/export loses important record types, plaintext TXT export needs extreme care, and current consumer documentation doesn't establish a mature family/recovery system or a product-specific public cryptographic audit at the level we want.

In the United States, the verdict isn't a score: don't deploy it. A password manager must have a reliable update path. Existing users should make a controlled migration, rotate credentials generated by affected old clients, verify passkeys and TOTP separately, and delete every plaintext export after import.

For supported-region buyers, keep Kaspersky only if the bundle, interface and existing ecosystem genuinely reduce friction. Don't move a healthy Bitwarden, 1Password, Proton Pass or KeePassXC vault merely because Password Manager appears inside an antivirus subscription.