LocalPassMass — Local Password Manager for Chrome
Your passwords stay on your device.
Your passwords stay on your device.
LocalPassMass is a local-only password manager for Google Chrome on Windows. It gives you fast autofill, encrypted password storage, password history, secure backups, recovery keys, and a built-in password generator without requiring a cloud account or password synchronization server.
Your vault stays inside your Chrome profile in encrypted form.
A Password Manager Without Cloud Sync
Most password managers are built around accounts, remote servers, and synchronization.
LocalPassMass takes a different approach.
Your active password vault is stored locally inside Chrome and encrypted before it is written to browser storage.
There is no LocalPassMass account to create and no password synchronization service required to use the extension.
For people who prefer keeping their password vault under their own control, LocalPassMass keeps the workflow simple:
Save locally. Back up securely. Recover with your own key.
Built for Everyday Use
LocalPassMass is designed to stay out of the way until you need it.
When a saved login is available for a website, click or focus the username or password field and a compact credential selector appears beside the form.
Choose the account you want and LocalPassMass fills the matching credentials.
No large overlay. No separate login page. No automatic form submission.
Features
Local Encrypted Vault
Saved usernames, passwords, secure notes, and password history are stored inside an encrypted local vault.
Opening the vault data or an exported backup with a normal text editor does not reveal your passwords as readable text.
Website Autofill
Saved credentials can be suggested directly beside login fields.
LocalPassMass supports standard username and password fields and keeps autofill user-triggered.
Subdomain Support
A credential associated with:
example.com
can also be available on related addresses such as:
login.example.com
and:
accounts.example.com
Domain matching is designed to avoid treating unrelated look-alike domains such as evil-example.com as the same website.
Password History
Changing a password does not have to destroy the previous value immediately.
LocalPassMass can retain up to 25 previous password versions inside the encrypted vault.
Older passwords can be reviewed or copied when needed.
Password Generator
Generate passwords between:
4–128 characters
Choose whether to include:
- Uppercase letters
- Lowercase letters
- Numbers
- Symbols
Generation happens locally in the browser.
Password Health
LocalPassMass can identify basic password issues including:
- Reused passwords
- Short or simple passwords
- Older passwords
The check is performed locally against your own vault.
Password Reuse Warning
If you attempt to save a password already used by another account, LocalPassMass can warn you before saving it.
The warning is informational. You remain in control of the final decision.
Encrypted Backup
Export your vault to a .svault backup file.
The backup contains encrypted vault data and is designed to be stored on your own trusted storage device.
Recovery Key
LocalPassMass generates a separate Recovery Key for backup recovery.
The Recovery Key should be stored separately from the backup itself.
This gives you an offline recovery path without relying on an online account recovery service.
Backup Reminders
Because LocalPassMass is local-only, maintaining a backup matters.
The extension can remind you when:
- You have never created a backup
- Several changes have been made since your last backup
- Your existing backup is getting old
Automatic Locking
Configure how long the vault can remain unlocked after inactivity.
Restarting Chrome also locks the active vault session.
Emergency Lock
Use:
Ctrl + Shift + L
to lock LocalPassMass immediately.
Clipboard Auto-Clear
Copied passwords can automatically be removed from the clipboard after a configurable delay.
Recently Used Accounts
When several credentials are stored for the same website, favorites and recently used accounts are prioritized so common logins stay easy to reach.
Secure Notes
Store small account-related notes alongside a credential.
Secure notes remain inside the encrypted vault.
Local-Only by Design
LocalPassMass does not use a cloud password synchronization service.
Core vault operations happen locally, including:
- Unlocking your vault
- Reading saved credentials
- Password generation
- Password history
- Password Health
- Backup creation
- Backup recovery
The extension itself does not need an Internet connection for these operations.
Naturally, signing into a website still requires whatever network connection that website normally uses.
What Local-Only Means
Local-only storage gives you more direct control over where your vault exists.
It also means you are responsible for keeping a usable backup.
If your Chrome profile, Windows installation, or storage device is permanently lost and you do not have a valid backup and Recovery Key, LocalPassMass cannot retrieve your passwords from a remote server.
There is no remote copy to fall back on.
That is intentional.
Backup Is Part of the Setup
For regular use, keep:
- At least one recent
.svaultbackup. - Your Recovery Key in a separate location.
- Preferably another backup copy on a second trusted storage device.
Do not keep your only backup and only Recovery Key together.
A backup stored on the same disk as the active Chrome profile does not protect you from disk failure.
Security Model
LocalPassMass currently uses:
Vault encryption: AES-256-GCM
Vault key: Random 256-bit key
Master Password derivation: PBKDF2-SHA256
PBKDF2 iterations: 600,000
Backup recovery: Separate random 256-bit Recovery Key
Browser: Google Chrome
Platform: Windows
Cloud synchronization: None
The active encrypted vault is stored in Chrome extension storage.
An unlocked session key is kept separately for the active browser session and is removed when the vault is locked.
Simple Master Passwords Are Allowed
LocalPassMass does not force a particular Master Password format.
You can use a numeric PIN or a short password if that matches your workflow.
However, convenience changes the security tradeoff.
If someone obtains a complete copy of your Chrome profile, a short Master Password is easier to guess than a long unique password.
For stronger local protection, use a Master Password that is both unique and difficult to guess.
HTTP Autofill Is Disabled by Default
LocalPassMass does not normally offer credentials on unencrypted HTTP websites.
You can change this behavior in Settings, but HTTPS is recommended for sites where credentials are entered.
No Automatic Login Submission
LocalPassMass fills credentials only after you select an account.
It does not automatically submit the login form.
This gives you a chance to confirm the website and selected account before signing in.
No Account Required
There is no LocalPassMass cloud account required for the local vault.
Install the extension, create your Master Password, save the Recovery Key, and start using it.
Download LocalPassMass
Download the latest ZIP release and install it as an unpacked Chrome extension.
Before updating an existing installation, create a fresh backup.
If you are updating from an older LocalPassMass version, keep the existing Chrome extension installation and replace the files in the same extension directory.
Detailed installation and upgrade instructions are available in the documentation.
Documentation
Read the complete LocalPassMass documentation for:
- Installation
- First-time setup
- Autofill
- Backups
- Recovery
- Password History
- Updates
- Moving to another computer
- Troubleshooting
Documentation:
https://inaser.ir/documents/localpassmass-documentation
Open Source
The LocalPassMass source code and releases are available on GitHub.
GitHub:
https://github.com/n4ser/LocalPassMass
Review the source, report issues, follow development, or download available releases directly from the repository.
LocalPassMass Pro
A Pro edition can extend the LocalPassMass experience with additional features while keeping the core local-first approach.
Use the purchase option on this page when Pro becomes available.
Current Release
LocalPassMass 1.2.0
Highlights:
- Field-anchored autofill menu
- Compact flat interface
- Password History
- 30-second encrypted save prompt
- Public-Suffix-aware subdomain matching
- Password Health
- Password reuse warnings
- Recent-first credential suggestions
- Encrypted
.svaultbackups - Recovery Key support
- Backup reminders
- Local documentation and security improvements
Requirements
Google Chrome
Windows
LocalPassMass is currently distributed as an unpacked Chrome extension.
Important Before Removing the Extension
Your active vault is local.
Before removing LocalPassMass, deleting your Chrome profile, reinstalling Windows, or moving to another computer, create a current backup and make sure you still have the matching Recovery Key.
Do not treat the extension directory itself as your backup.
Community reviews & questions
No reviews or questions yet. Be the first to leave one.