Skip to content

LocalPassMass — Local Password Manager for Chrome

Your passwords stay on your device.

Your passwords stay on your device.

LocalPassMass is a local-only password manager for Google Chrome on Windows. It gives you fast autofill, encrypted password storage, password history, secure backups, recovery keys, and a built-in password generator without requiring a cloud account or password synchronization server.

Your vault stays inside your Chrome profile in encrypted form.

A Password Manager Without Cloud Sync

Most password managers are built around accounts, remote servers, and synchronization.

LocalPassMass takes a different approach.

Your active password vault is stored locally inside Chrome and encrypted before it is written to browser storage.

There is no LocalPassMass account to create and no password synchronization service required to use the extension.

For people who prefer keeping their password vault under their own control, LocalPassMass keeps the workflow simple:

Save locally. Back up securely. Recover with your own key.

Built for Everyday Use

LocalPassMass is designed to stay out of the way until you need it.

When a saved login is available for a website, click or focus the username or password field and a compact credential selector appears beside the form.

Choose the account you want and LocalPassMass fills the matching credentials.

No large overlay. No separate login page. No automatic form submission.

Features

Local Encrypted Vault

Saved usernames, passwords, secure notes, and password history are stored inside an encrypted local vault.

Opening the vault data or an exported backup with a normal text editor does not reveal your passwords as readable text.

Website Autofill

Saved credentials can be suggested directly beside login fields.

LocalPassMass supports standard username and password fields and keeps autofill user-triggered.

Subdomain Support

A credential associated with:

example.com

can also be available on related addresses such as:

login.example.com

and:

accounts.example.com

Domain matching is designed to avoid treating unrelated look-alike domains such as evil-example.com as the same website.

Password History

Changing a password does not have to destroy the previous value immediately.

LocalPassMass can retain up to 25 previous password versions inside the encrypted vault.

Older passwords can be reviewed or copied when needed.

Password Generator

Generate passwords between:

4–128 characters

Choose whether to include:

  • Uppercase letters
  • Lowercase letters
  • Numbers
  • Symbols

Generation happens locally in the browser.

Password Health

LocalPassMass can identify basic password issues including:

  • Reused passwords
  • Short or simple passwords
  • Older passwords

The check is performed locally against your own vault.

Password Reuse Warning

If you attempt to save a password already used by another account, LocalPassMass can warn you before saving it.

The warning is informational. You remain in control of the final decision.

Encrypted Backup

Export your vault to a .svault backup file.

The backup contains encrypted vault data and is designed to be stored on your own trusted storage device.

Recovery Key

LocalPassMass generates a separate Recovery Key for backup recovery.

The Recovery Key should be stored separately from the backup itself.

This gives you an offline recovery path without relying on an online account recovery service.

Backup Reminders

Because LocalPassMass is local-only, maintaining a backup matters.

The extension can remind you when:

  • You have never created a backup
  • Several changes have been made since your last backup
  • Your existing backup is getting old

Automatic Locking

Configure how long the vault can remain unlocked after inactivity.

Restarting Chrome also locks the active vault session.

Emergency Lock

Use:

Ctrl + Shift + L

to lock LocalPassMass immediately.

Clipboard Auto-Clear

Copied passwords can automatically be removed from the clipboard after a configurable delay.

Recently Used Accounts

When several credentials are stored for the same website, favorites and recently used accounts are prioritized so common logins stay easy to reach.

Secure Notes

Store small account-related notes alongside a credential.

Secure notes remain inside the encrypted vault.

Local-Only by Design

LocalPassMass does not use a cloud password synchronization service.

Core vault operations happen locally, including:

  • Unlocking your vault
  • Reading saved credentials
  • Password generation
  • Password history
  • Password Health
  • Backup creation
  • Backup recovery

The extension itself does not need an Internet connection for these operations.

Naturally, signing into a website still requires whatever network connection that website normally uses.

What Local-Only Means

Local-only storage gives you more direct control over where your vault exists.

It also means you are responsible for keeping a usable backup.

If your Chrome profile, Windows installation, or storage device is permanently lost and you do not have a valid backup and Recovery Key, LocalPassMass cannot retrieve your passwords from a remote server.

There is no remote copy to fall back on.

That is intentional.

Backup Is Part of the Setup

For regular use, keep:

  1. At least one recent .svault backup.
  2. Your Recovery Key in a separate location.
  3. Preferably another backup copy on a second trusted storage device.

Do not keep your only backup and only Recovery Key together.

A backup stored on the same disk as the active Chrome profile does not protect you from disk failure.

Security Model

LocalPassMass currently uses:

Vault encryption: AES-256-GCM

Vault key: Random 256-bit key

Master Password derivation: PBKDF2-SHA256

PBKDF2 iterations: 600,000

Backup recovery: Separate random 256-bit Recovery Key

Browser: Google Chrome

Platform: Windows

Cloud synchronization: None

The active encrypted vault is stored in Chrome extension storage.

An unlocked session key is kept separately for the active browser session and is removed when the vault is locked.

Simple Master Passwords Are Allowed

LocalPassMass does not force a particular Master Password format.

You can use a numeric PIN or a short password if that matches your workflow.

However, convenience changes the security tradeoff.

If someone obtains a complete copy of your Chrome profile, a short Master Password is easier to guess than a long unique password.

For stronger local protection, use a Master Password that is both unique and difficult to guess.

HTTP Autofill Is Disabled by Default

LocalPassMass does not normally offer credentials on unencrypted HTTP websites.

You can change this behavior in Settings, but HTTPS is recommended for sites where credentials are entered.

No Automatic Login Submission

LocalPassMass fills credentials only after you select an account.

It does not automatically submit the login form.

This gives you a chance to confirm the website and selected account before signing in.

No Account Required

There is no LocalPassMass cloud account required for the local vault.

Install the extension, create your Master Password, save the Recovery Key, and start using it.

Download LocalPassMass

Download the latest ZIP release and install it as an unpacked Chrome extension.

Before updating an existing installation, create a fresh backup.

If you are updating from an older LocalPassMass version, keep the existing Chrome extension installation and replace the files in the same extension directory.

Detailed installation and upgrade instructions are available in the documentation.

Documentation

Read the complete LocalPassMass documentation for:

  • Installation
  • First-time setup
  • Autofill
  • Backups
  • Recovery
  • Password History
  • Updates
  • Moving to another computer
  • Troubleshooting

Documentation:

https://inaser.ir/documents/localpassmass-documentation

Open Source

The LocalPassMass source code and releases are available on GitHub.

GitHub:

https://github.com/n4ser/LocalPassMass

Review the source, report issues, follow development, or download available releases directly from the repository.

LocalPassMass Pro

A Pro edition can extend the LocalPassMass experience with additional features while keeping the core local-first approach.

Use the purchase option on this page when Pro becomes available.

Current Release

LocalPassMass 1.2.0

Highlights:

  • Field-anchored autofill menu
  • Compact flat interface
  • Password History
  • 30-second encrypted save prompt
  • Public-Suffix-aware subdomain matching
  • Password Health
  • Password reuse warnings
  • Recent-first credential suggestions
  • Encrypted .svault backups
  • Recovery Key support
  • Backup reminders
  • Local documentation and security improvements

Requirements

Google Chrome

Windows

LocalPassMass is currently distributed as an unpacked Chrome extension.

Important Before Removing the Extension

Your active vault is local.

Before removing LocalPassMass, deleting your Chrome profile, reinstalling Windows, or moving to another computer, create a current backup and make sure you still have the matching Recovery Key.

Do not treat the extension directory itself as your backup.

Community reviews & questions

No reviews or questions yet. Be the first to leave one.

Leave a review or question

Rating (optional)