HIGH SALIENCE / RESEARCH / PASSWORD MANAGER TEARDOWN
TEARDOWN 10 · PUBLISHED SEPTEMBER 26, 2026 · DATASET INCLUDED
100 Questions, Tenth Category: Password Managers, Where ChatGPT Picks Bitwarden in 78 Answers and LastPass Barely Comes Up Unless You Ask
Tenth category, same method: 100 password manager queries, ChatGPT with web search on, every answer coded by two independent AI readers, Google's top ten as a control. This is the most one-sided category so far. Bitwarden is named in 84 answers, recommended in 82 and picked as the answer's own choice in 78, more than any brand in the nine earlier teardowns, and the model builds those answers mostly from the vendors' own websites. LastPass, one of the category's best-known names, barely comes up unless the question asks about it.
01Method
Same query structure, same coding, one new category.
Queries: 100 password managers queries built from the same templates as the earlier teardowns: 30 category, 30 comparison, 20 alternative and 20 recommendation. The full list is in the dataset.
Surface: ChatGPT with web search forced on, logged out, United States, English, via the DataForSEO scraper, one run per query, collected September 26, 2026.
Control: Google's top ten organic results for the same queries in the same window, via the DataForSEO SERP API at depth 20 and truncated to the first ten organic results.
Coding: every answer was coded by two independent AI readers (Claude agents working blind from a written protocol), with a third settling disagreements. They were not people. Each brand named was coded picked (the answer's own verdict: "my pick", "choose X if", a shortlist it tells you to act on, the #1 of its ranking), recommended (assigned to a stated case or fit, such as "best for small teams", without being the answer's verdict), listed (named as an option, no fit given), passing (named but not offered as an option) or anchor (the brand being replaced in an "alternatives" query), against a 35-brand dictionary fixed before coding (see the collection note), under codebook v2.0. "Recommended" in the tables includes picked brands. The two readers agreed on 95.7% of brand codes in this teardown (98.8% at the recommended level). Cited URLs were deduplicated to their domain and classed as first-party or third-party. The third reader decided 15 of the 346 brand codes in this teardown. A rules-based first pass (the codebook v1.6 rules) agreed with the final codes on 96.5 percent at the recommended level; only the reader codes are published. The readers also coded 14 brand mentions that no dictionary alias matched (named by meaning or only by a web address); those rows are in the dataset.
Collection note: the ChatGPT answers and the Google controls were collected on September 26, 2026 through the DataForSEO standard queue, with raw responses saved exactly as returned. One ChatGPT task returned no result and was re-run once through the same queue. CyberArk is matched on cyberark.com only, although that address now redirects to Palo Alto Networks. wired.com and security.org are not on the codebook's review-and-media list, the same list every teardown uses, so they count as other third-party pages.
One run per query, so this is a teardown, not the benchmark. Frequencies describe this window only. Absence means not observed in this sample, never zero visibility.
02Findings
One default, a vendor-written reading list, and a fallen leader.
| Brand | Appears in | Recommended in | Picked in | Picked share of appearances |
|---|---|---|---|---|
| Bitwarden | 84 | 82 | 78 | 93% |
| 1Password | 67 | 65 | 59 | 88% |
| Proton Pass | 38 | 36 | 27 | 71% |
| Dashlane | 28 | 26 | 15 | 54% |
| Keeper | 25 | 25 | 21 | 84% |
| KeePassXC | 22 | 22 | 16 | 73% |
| Apple Passwords | 15 | 14 | 8 | 53% |
| NordPass | 12 | 9 | 5 | 42% |
Each linked brand has its own page: how ChatGPT recommends every brand in this dataset, with positioning labels, head-to-head results and sources.
Out of 100 answers, codebook v2.0. "Picked" means the answer itself chose the brand as its verdict, overall or for a case. "Recommended" means the answer assigned the brand to a stated case or fit, and includes picked brands. "Appears" adds brands named as an option with no fit. The brand being replaced in an "alternatives" query is excluded from all columns.
The strongest default in the series
Bitwarden is named in 84 of 100 answers, recommended in 82 and picked in 78. No brand in the nine earlier teardowns reached any of those numbers; the previous highs were 75 named (QuickBooks and HubSpot), 74 recommended (HubSpot) and 70 picked (Asana). Eighty of the 100 questions do not mention Bitwarden, and it is picked in 60 of those answers. 1Password is a clear second, named in 67, recommended in 65 and picked in 59. The two are picked together in 49 answers, typically 1Password for the most polished experience and Bitwarden for price, open source and self-hosting. Of the 93 answers that pick anything, 88 pick one or both.
Everyone else is a lane
Proton Pass is named in 38 answers, recommended in 36 and picked in 27, usually for privacy. Keeper is picked in 21 of the 25 answers that name it, 14 of them to questions framed around a business or team, and in all four healthcare, law firm and MSP questions that produced a pick. KeePassXC is picked in 16 of 22, for offline, local-file control, 11 of them in the 20 alternatives questions. Dashlane has the widest gap between being described and being chosen: recommended in 26 answers, picked in 15. Apple Passwords is recommended in 14 and picked in 8, almost always for people who use only Apple devices.
LastPass has almost disappeared
Eleven of the 100 questions name LastPass. In the other 89 answers it is named twice: once in a healthcare table and once as a cited blog. When a question does ask about it, 6 of the 11 answers bring up its 2022 security incident. In the six head-to-heads that name it, LastPass is picked in three, each time on a condition such as wanting a free option or already being invested in it; the other side is picked in five, and one answer picks neither. For one of the best-known names in the category, that is a striking absence, and a sign of how a reputation event can carry into AI answers.
Decisive answers, from sites that do not rank
Ninety-three of the 100 answers pick at least one brand, and 27 of the 30 head-to-heads pick every brand named. Nineteen of the 20 direct advice questions produced a pick, with Bitwarden among the picks in 18 and 1Password in 17; the one without a pick, for a healthcare practice, asked how many users the practice has and which office suite it runs, and named no product. Of the 241 picks, 163 went to brands whose own website did not rank in Google's top ten for that question, 68 percent. Bitwarden's site ranked for 41 of its 78 picks, 1Password's for 14 of its 59. Google's top ten is 87 percent third-party pages, level with applicant tracking as the highest in the series.
The vendors write the reading list
Across 100 answers there were 292 citation events to 77 domains. Vendors' own sites took 201 of them, 69 percent, the highest share in the series, and 65 answers cited nothing but vendor pages, also the highest. bitwarden.com alone is cited in 64 answers, 45 of them to questions that never mention Bitwarden, and Bitwarden is picked in 41 of those 45. 1password.com is cited in 52 answers and proton.me in 28. The most-cited independent sources are Wired (10) and security.org (8). Reddit and Wikipedia have zero citations, for the tenth teardown running.
Seventy-eight of the 292 citation events involved a domain that also sat in Google's top ten for that query, 27 percent.
0310 categories, side by side
Same rulebook, every category so far.
| Measure (codebook v2.0) | Project management, Sept 8 | CRM, Sept 17 | Email marketing, Sept 17 | Help desk, Sept 17 | Accounting, Sept 17 | Payment processing, Sept 17 | Payroll, Sept 21 | HR software, Sept 26 | Applicant tracking, Sept 26 | Password managers, Sept 26 |
|---|---|---|---|---|---|---|---|---|---|---|
| Recommendations per category answer (average) | 5.9 | 4.3 | 5.0 | 5.5 | 4.3 | 4.2 | 4.6 | 5.0 | 4.5 | 3.4 |
| Answers with no recommended dictionary brand | 1 of 100 | 5 of 100 | 1 of 100 | 1 of 100 | 0 of 100 | 5 of 100 | 1 of 100 | 6 of 100 | 5 of 100 | 3 of 100 |
| Answers with no pick (the answer's own verdict) | 2 of 100 | 11 of 100 | 2 of 100 | 4 of 100 | 9 of 100 | 22 of 100 | 19 of 100 | 17 of 100 | 12 of 100 | 7 of 100 |
| Most-recommended brand: appears / recommended | Asana 73 / 73 | HubSpot 75 / 74 | Mailchimp 58 / 56 | Zendesk 70 / 69 | QuickBooks 75 / 73 | Stripe 70 / 68 | Gusto 73 / 73 | Rippling 58 / 57 | Workable 53 / 52 | Bitwarden 84 / 82 |
| Most-picked brand: appears / picked | Asana 73 / 70 | HubSpot 75 / 69 | Mailchimp 58 / 44 | Zendesk 70 / 61 | QuickBooks 75 / 65 | Stripe 70 / 54 | Gusto 73 / 61 | Rippling 58 / 50 | Workable 53 / 47 | Bitwarden 84 / 78 |
| Head-to-head queries recommending every named brand | 30 of 30 | 28 of 30 | 30 of 30 | 29 of 30 | 26 of 30 | 28 of 30 | 30 of 30 | 28 of 30 | 29 of 30 | 28 of 30 |
| Head-to-head queries picking every named brand | 30 of 30 | 23 of 30 | 29 of 30 | 29 of 30 | 25 of 30 | 19 of 30 | 21 of 30 | 21 of 30 | 29 of 30 | 27 of 30 |
| Recommendation-intent queries with a dictionary recommendation | 19 of 20 | 18 of 20 | 20 of 20 | 20 of 20 | 20 of 20 | 19 of 20 | 20 of 20 | 18 of 20 | 20 of 20 | 19 of 20 |
| Recommendation-intent queries with a pick | 19 of 20 | 18 of 20 | 20 of 20 | 20 of 20 | 19 of 20 | 18 of 20 | 20 of 20 | 18 of 20 | 20 of 20 | 19 of 20 |
| Recommended mentions where the brand does not rank in Google's top 10 | 398 of 468 (85%) | 269 of 387 (70%) | 313 of 419 (75%) | 350 of 445 (79%) | 206 of 368 (56%) | 294 of 360 (82%) | 202 of 383 (53%) | 310 of 405 (77%) | 333 of 388 (86%) | 218 of 304 (72%) |
| Picked mentions where the brand does not rank in Google's top 10 | 349 of 416 (84%) | 226 of 330 (68%) | 270 of 370 (73%) | 291 of 380 (77%) | 141 of 279 (51%) | 170 of 222 (77%) | 113 of 246 (46%) | 232 of 311 (75%) | 261 of 311 (84%) | 163 of 241 (68%) |
| Google top 10 that is third-party pages | 746 of 1,000 (75%) | 710 of 1,000 (71%) | 720 of 1,000 (72%) | 714 of 1,000 (71%) | 743 of 1,000 (74%) | 787 of 1,000 (79%) | 653 of 1,000 (65%) | 820 of 1,000 (82%) | 871 of 1,000 (87%) | 866 of 1,000 (87%) |
| Citation events to vendors' own sites | 216 of 362 (60%) | 136 of 320 (42%) | 193 of 367 (53%) | 152 of 345 (44%) | 125 of 302 (41%) | 161 of 301 (53%) | 192 of 314 (61%) | 167 of 325 (51%) | 139 of 311 (45%) | 201 of 292 (69%) |
| Answers citing only vendor pages | 50 of 100 | 40 of 100 | 37 of 100 | 27 of 100 | 34 of 100 | 47 of 100 | 49 of 100 | 34 of 100 | 30 of 100 | 65 of 100 |
| Share of citations in the 10 most-cited domains | 54% | 40% | 42% | 45% | 55% | 58% | 55% | 46% | 44% | 72% |
| Citation events whose domain is in Google's top 10 | 83 of 362 (23%) | 83 of 320 (26%) | 97 of 367 (26%) | 80 of 345 (23%) | 99 of 302 (33%) | 98 of 301 (33%) | 134 of 314 (43%) | 85 of 325 (26%) | 59 of 311 (19%) | 78 of 292 (27%) |
| Reddit and Wikipedia citations | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
All columns are coded under codebook v2.0 by two independent AI readers per answer; the project management column is the September 8 dataset recoded under it. Each teardown is one run per query in its own window, so differences between columns mix category with collection date.
04What this changes
Four things, in order.
Your own site can be the category's textbook. bitwarden.com was cited in 45 answers to questions that do not mention Bitwarden, and Bitwarden was picked in 41 of them. Clear comparison, pricing and security pages are the material the model reaches for first in this category.
Reputation events show up in the answer. LastPass is still a working product with business customers, but the model mentions it almost only when asked, and then with its breach. Recovering from an event like that means changing what the sources say, not just the product.
Being described is not being chosen. When the model offers two brands as the standard choice, every other vendor is competing for a lane. Keeper, with a plain business and compliance lane, is picked in 21 of the 25 answers that name it; Dashlane is picked in 15 of 28. Name your lane plainly.
Being built in is not being chosen. Apple Passwords and Google Password Manager ship with Apple devices and Chrome, yet they were picked in 9 answers between them, 5 of those to questions that name an Apple device or the product itself. Default availability does not make you the model's answer.
05Limitations
What this teardown cannot tell you.
One run per query means answer variance is unmeasured; Benchmark 01 runs each query three times across three surfaces. The teardowns are collected on different days, so differences between categories mix the category with the date. The brand dictionary covers the general password managers market and deliberately excludes vertical tools, so their appearances are described in prose and not counted. The readers are AI models, not people: they follow a written protocol and agree with each other closely, but a shared blind spot would not show up as disagreement. The line between picked and recommended is a judgment, documented in the protocol with examples. Sentiment is not coded. No vendor-tool cross-check was read for this category. Google's control counts a brand as ranking only when its own domain is in the top ten; a listicle that features the brand does not count. One run per question, one day, United States, English, logged out. Answers vary between runs, so these are frequencies for this sample. The readers are AI models, not people, and the line between picked and recommended is a judgment call; the third reader decided 15 codes in this teardown. The review-and-media list is the codebook's fixed list, so publishers such as Wired count as other third-party pages here.
06Dataset
Check it, don't believe it.
Every number above can be recomputed from these files. CC BY 4.0: use them, cite the page.
- queries.csv: the 100 queries with intent labels.
- brands.csv: the 35-brand dictionary with aliases and canonical domains.
- mentions.csv: 346 coded brand mentions with position, type, a 0/1 picked column and whether the brand's domain was in Google's top ten.
- citations.csv: 292 citation events with domain class and Google overlap.
- observations.csv: one row per query with brand, recommendation, citation and control counts.
- coder-notes.md: coding notes: reader method and agreement, judgment calls that matter in this category, reader-added mentions and dictionary notes
- codebook.md: the rulebook, with dated amendments through v2.0.
- reader-protocol.md: the written protocol both readers coded against (codebook v2.0).
- picked_stats.json: the picked-level figures.
The earlier teardowns: Teardown 01, project management, Teardown 02, crm, Teardown 03, email marketing, Teardown 04, help desk, Teardown 05, accounting, Teardown 06, payment processing, Teardown 07, payroll, Teardown 08, hr software, Teardown 09, applicant tracking.
Ten categories, and the reading list is still the story.
In password managers the model's reading list is mostly the vendors' own websites, 69 percent of citations, the highest share in the series so far, and the brand whose site is cited most is the one it picks most. Finding out what the model is reading for your category is the first thing a Category Salience Brief does, with a query set you approve first.