
Evaluating the Efficiency of Password Managers Against Real-World Phishing Pages – Volume 12 Issue 5

International Journal of Computer Techniques
ISSN 2394-2231
Volume 12, Issue 5 | Published: September β October 2025
Author
Mulla Mohsin Azimmohammed , Huzaif Shaikh Ismail Sofisarmast
Table of Contents
ToggleAbstract
This study checks how password managers behave when visiting on realistic phishing pages. Testing was done in a virtual machine using Caniphish templates and XAMPP with host file trick. both browser managers including Chrome, Brave, Edge and Firefox and Standalone password managers including Bitwarden, Lastpass, Keepassxc, Proton Pass were manually tested. Findings indicate that the majority of password managers detected domain inconsistencies and prevented automatic credential filling, while certain cases necessitated manual input, and several browsers restricted access to websites because of certificate validation issues. This shows managers give safety in many cases but not always the same way. This research helps users know the limits of password managers. And also help the password manager developers make better systems.
Keywords
password managers, phishing, autofill, browser security, authentication, cybersecurity.Conclusion
The experimental evaluation conducted in this study demonstrates that password management tools typically succeed in preventing phishing attempts, though they are not without limitations. There are still minor cases where partial data is leaked or warnings may not be clear enough for the user. Results show that password managers while can provide you good security users too have to be careful when you are on the internet. The suggestions made here can help users be more secure, and also help the password manager developers make better systems.
References
[1]B. Krishna, A. Arya, A. Krishna, R. Zakarias, and S. E. Anto, βSurvey on Password Managers,β International Journal of Advance Research (IJARIIE), 2025. [2]N. Alkaldi and K. Renaud, βWhy Do People Adopt, or Reject, Smartphone Password Managers?,β EuroUSEC, Jul. 2016. [3]H. Alshahrani and A. Alghamdi, βThe Factors Influencing the Use of Password Managers,β JISCR, Jun. 2022. [4]D. Silver, S. Jana, D. Boneh, E. Chen, and C. Jackson, βPassword Managers: Attacks and Defenses,β USENIX Security Symposium, Aug. 2014. [5]S. Oesch and S. Ruoti, βThat Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Browser-Based Password Managers,β USENIX Security Symposium, Aug. 2020. [6]P. Gallus, D. StanΔk, and I. Klaban, βSecurity Evaluation of Password Managers: A Comparative Analysis and Penetration Testing of Existing Solutions,β International Conference on Cyber Warfare and Security (ICCWS), Mar. 2025. [7]A. FΓ‘brega, A. Namavari, R. Agarwal, B. Nassi, and T. Ristenpart, βExploiting Leakage in Password Managers via Injection Attacks,β arXiv, Jan. 2023. [8]T. S. Oesch, βAn Analysis of Modern Password Manager Security and Usage on Desktop and Mobile Devices,β University of Tennessee, May 2021. [9]H. Ray, F. Wolf, and R. Kuber, βWhy Older Adults (Donβt) Use Password Managers,β USENIX, Aug. 2021. [10]A. Hutchinson, J. Tang, A. J. Aviv, and P. Story, βMeasuring the Prevalence of Password Manager Issues Using In-Situ Experiments,β NDSS Symposium, Feb. 2024. [11]B. Naqvi, K. Perovaa, A. Farooqb, I. Makhdoomd, S. Oyedeji, and J. Porras, βMitigation Strategies Against the Phishing Attacks,β Elsevier, Jul. 2023. A. Gautam, T. K. Yadav, K. Seamons, and S. Ruoti, βPasswords Are Meant to Be Secret: A Practical Secure Password Entry Channel for Web Browsers,β arXiv, Feb. 2024.
IJCT Important Links
Β© 2025 International Journal of Computer Techniques (IJCT).







