shouldiuse.io

Categories

VERDICT

Should I use Pwpush (Password Pusher)?

Share passwords securely with self-destructing links - pwpush.com

Worth it. Buy if you're an IT team or MSP sharing one-off credentials — the free hosted tier covers most needs. Skip it as a password manager or enterprise secrets vault; that's 1Password or Bitwarden territory.

Confidence

Medium. Based on 40+ public sources; formal review coverage is thin, so confidence rests mainly on Reddit consensus and official docs.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo evidence found
  • Security posture

Pricing

Free

Hosted Free

ModelOpen source
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Self-Hosted Pro$59/mo ($708/yr)

Best for

  • IT teams sharing one-off credentials
  • MSPs handing passwords to clients
  • Onboarding and offboarding handoffs
  • Self-hosters who want open source

Not for

  • Anyone wanting a password manager — use 1Password or Bitwarden
  • Teams needing ongoing credential storage, not one-time links
  • Compliance-heavy orgs that can't accept recent auth-bypass CVEs
  • Non-technical users who won't read docs or manage expiries

Gotchas - check before you buy

high

Multiple 2024–2026 security advisories; self-hosters must patch promptly

medium

Hosted pricing was restructured September 2026 — verify current tiers before committing

medium

Self-hosted Pro is $59/month ($708 annual commitment) — steep for a small team

low

Free users get docs and community support, not account-level help

Pros and cons

Pros

  • Free to use hosted; open source and self-hostable via Docker
  • Expiring, view-limited links keep passwords out of email and tickets
  • Trusted by sysadmins and MSPs for client credential handoffs
  • Authenticated recipients verify who viewed your secrets
  • CLI and API enable automation

Cons

  • 2026 auth-bypass CVE on a security tool
  • 2024 rate-limiter bypass advisory
  • Reviewers call the feature set light versus competitors
  • Almost no third-party review coverage
  • Self-hosting shifts all security patching onto you

Sources & method

Analyzed 10/06/2026 - 10 sources - Multiple advisories, including a 2026 auth-bypass CVE; open-source code with published encryption docs.

official x4review x4security x2
  • CVE-2026-41308: Auth Bypass, Authentication bypass flaw disclosed May 18, 2026.
  • Rate limiter bypass, Advisory GHSA-ffp2-8p2h-4m5j: rate limiter could be bypassed by forging headers (Nov 2024).
  • TOCTOU race condition, A time-of-check-to-time-of-use race condition was catalogued against pwpush.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Free core; Pro only needed at scale
  • Ease of use: 4/5. Paste, set expiry, send link
  • Feature depth: 3/5. Deliberately narrow; reviewers say light on features
  • Support quality. No evidence found
  • Security posture: 2/5. 2026 auth-bypass CVE plus earlier advisories
  • Free Hosted price Basic use of pwpush.com costs nothing
  • $59/mo Self-hosted Pro $708 billed annually
  • Open source Source model Self-host via Docker or use hosted

Pricing

Hosted Free

Free

  • Basic expiring pushes on pwpush.com
  • No signup required for core use

Self-Hosted Pro

$59/mo ($708/yr)

  • Run Pro on your own infrastructure
  • Premium features for self-hosters

Security

Multiple advisories, including a 2026 auth-bypass CVE; open-source code with published encryption docs.

  • CVE-2026-41308: Auth BypassAuthentication bypass flaw disclosed May 18, 2026.⁴
  • Rate limiter bypassAdvisory GHSA-ffp2-8p2h-4m5j: rate limiter could be bypassed by forging headers (Nov 2024).⁵
  • TOCTOU race conditionA time-of-check-to-time-of-use race condition was catalogued against pwpush.

What users say

Sysadmins and MSPs on Reddit widely recommend it for one-time credential sharing, though some call it light on features.

“Pwpush is a reliable, le…”
Reddit, r/cybersecurity
“We use PWPush. https://p…”
Reddit, r/msp
“This is pretty light on feat…”
LibHunt comparison

Companies that use it

  • Butte College
  • Sincere ICT
Full analysis

Based on 40+ public sources; formal review coverage is thin, so confidence rests mainly on Reddit consensus and official docs.

Free, open-source expiring links for one-off password sharing. Great for IT handoffs; not a password manager.

Methodology

Based on 40+ public sources; formal review coverage is thin, so confidence rests mainly on Reddit consensus and official docs.

Sources

  1. Password Pusher FAQdocs.pwpush.com
    official
  2. official
  3. official
  4. security
  5. security
  6. review
  7. review
  8. review
  9. review
  10. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.