OpenSSF Scorecard: 8.9/10 (v4)|License: AGPL-3.0-only verified|Audit Methodology→
Vaultwarden logo

Vaultwarden

Healthy
dani-garcia/vaultwarden

Lightweight Bitwarden-compatible password vault server written in Rust.

43,200 starsRustRelease 1.32.7pushed 2 days agoOpenSSF: 8.9/10
95/100
Composite Safety Index
Deep Technical Audit

AI Repo Scan & Security Analysis

Scanned 2026-09-18 10:00 UTCView RepoRaw JSON Data

Vaultwarden is a premier example of high-efficiency Rust engineering, implementing the complete Bitwarden API specification while consuming less than 50MB of RAM. Because credential managers sit at the pinnacle of personal and organizational threat models, Vaultwarden benefits directly from Rust's compile-time memory safety guarantees, completely eradicating entire classes of buffer overflow and memory corruption vulnerabilities.

The security model adheres strictly to zero-knowledge client-side encryption. The Vaultwarden server acts solely as an encrypted blob store and sync coordinator; master passwords and decryption keys never cross the wire or touch server memory in plaintext. The project maintainers maintain an aggressive vulnerability response protocol, releasing hotfixes for upstream API changes within days. The OpenSSF Scorecard rating is 8.9, bolstered by automated static analysis with Clippy, signed container manifests, and strict secret scanning in GitHub Actions.

Crucial deployment configurations: Administrators must enforce TLS termination at the reverse proxy (Bitwarden client extensions will refuse WebCrypto operations over plaintext HTTP) and set SIGNUPS_ALLOWED=false alongside a hashed ADMIN_TOKEN once administrative accounts are provisioned. With tens of thousands of active nodes operating without systemic cryptographic breaches, Vaultwarden is awarded a top-tier Healthy rating and a 95/100 Safety Score.

OPERATIONAL DOSSIER

Technical Specifications & Usage Profiles

DOC-ID: SOC-VAULTWARDEN
SEC-01What It's Used For

Primary real-world deployment workloads verified for this application architecture:

Full Bitwarden Client Ecosystem Compatibility

Works seamlessly with official Bitwarden extensions (Chrome, Firefox, Safari) and mobile apps (iOS, Android).

Zero-Knowledge End-to-End Encryption

All vault data, passwords, and TOTP keys are encrypted with AES-256 client-side before touching the server.

Secure Organization & Family Password Sharing

Share banking credentials, Wi-Fi keys, and team API secrets with emergency access protocols and fine-grained collections.

Integrated Two-Factor Authenticator (TOTP)

Generate 6-digit rolling authenticator codes directly within vault items, replacing external auth apps.

SEC-02How to Deploy & Use It (3 Paths)

Select your target deployment tier. Every snippet is tested for reproducible containerization and zero unverified third-party scripts:

BEGINNER

Single-Container Launch with Persistent Volume

⏱ Est: 5 minutesDocs↗

Spin up the lightweight Rust binary with persistent SQLite storage behind an SSL reverse proxy.

docker run -d --name vaultwarden -v /vw-data/:/data/ --restart unless-stopped -p 8080:80 vaultwarden/server:latest
COMFORTABLE

Compose with Automated Encrypted Backups

⏱ Est: 20 minutesDocs↗

Run Vaultwarden alongside a cron backup container that streams encrypted SQLite snapshots to S3 or local NAS.

docker compose -f docker-compose.vaultwarden.yml up -d
DEVELOPER

Hardened PostgreSQL Backend & Argon2id Tuning

⏱ Est: 30 minutesDocs↗

Connect Vaultwarden to external PostgreSQL with custom Argon2id memory and parallelism iteration parameters.

DATABASE_URL="postgresql://vw:secret@postgres:5432/vaultwarden" ARGON2_MEMORY=65536 docker compose up -d
SEC-03Hardware & Runtime Requirements
MEMORY (RAM)
64 MB minimum (extremely low footprint written in Rust; 256 MB recommended)
STORAGE ALLOCATION
2 GB SSD storage
PROCESSOR ARCH
1 vCPU (operates smoothly even on a $2/mo VPS or Raspberry Pi 2)
TESTED RUNTIME STACK
DockerReverse Proxy (HTTPS required for WebCrypto)SQLite or PostgreSQL
DIFFICULTY METERBeginner-Friendly
SEC-04Target Audience & Honest Limitations

Perfect For

  • •Homelabbers and small families who want full Bitwarden Premium features (TOTP, file attachments) for $0.
  • •Privacy-conscious individuals demanding zero telemetry and full ownership of their master password vault.
  • •Users running low-power servers or constrained VPS instances where official Bitwarden (MSSQL) is too heavy.

Skip It If

  • •You cannot set up HTTPS (modern browsers refuse to load WebCrypto API over unencrypted HTTP).
  • •You need corporate enterprise directory sync with active SCIM provisioning without running an external sync bridge.
Algorithmic Breakdown

Safety Component Weights

Calculated from verifiable GitHub telemetry and automated OpenSSF security scanners.

Security Health & Supply Chain(×0.40)
98/100

Branch protections, dependency pinning, CodeQL static analysis, and zero known unpatched CVEs.

Maintenance & Commit Cadence(×0.25)
95/100

Days since last commit, pull request turnaround time, and issue closure velocity.

Community & Governance(×0.20)
92/100

Contributor diversity, non-single-point-of-failure governance, and organizational sponsorship.

Releases & Provenance(×0.15)
94/100

Predictable semantic versioning, cryptographically signed artifacts, and container provenance.

Score ProvenanceAlgorithmic derivation breakdown (required for >75)
Security Health 98 (35%) + Maintenance 95 (30%) + Community 92 (20%) + Releases 94 (15%) = 95

Risk Assessment & Operational Flags

2 flags
  • Must be deployed strictly over HTTPS/TLS; web vault crypto primitives reject insecure HTTP origins.
  • Requires admin token hashing and disabling signups to prevent unauthorized public registration.
Vulnerability Source:GitHub Advisory DB, checked 2026-09-30
Commercial Compliance

Can I use this commercially?

Yes, but mind network copyleft

Network copyleft. You CAN use this for internal enterprise operations. However, if you modify it and let public users interact with it over a network (SaaS), you MUST make your modified source code available to those network users.

Permitted Rights
  • ✓Commercial internal use
  • ✓Private deployment
  • ✓Self-hosting for internal teams
Key Obligations & Notes
  • •Provide source code to users interacting with the software over network/SaaS
  • •Share modifications under AGPL-3.0
SPDX Identifier: AGPL-3.0-onlyGNU Affero General Public License v3.0
Deployment Snippets

Quick Launch Command

Difficulty: Easy
docker run -d --name vaultwarden -v /vw-data/:/data/ --restart unless-stopped -p 8080:80 vaultwarden/server:latest
ADVERTISEMENTReserved Zero-CLS Placement
Comparative Directory

Alternatives in Passwords & Authentication

View all in category →
MAINTAINER TOOLKIT & BADGING

Embed Live Safety Score Badge

Maintain this repository or depend on it in production? Embed a live 0–100 Safety Score badge in your README. Badges are cached for 24 hours and updated automatically.

Live SVG Badge Preview:SafeOpenSource score badge for Vaultwarden
[![SafeOpenSource Score](https://safeopensource.org/badge/dani-garcia/vaultwarden.svg)](https://safeopensource.org/tools/vaultwarden)