64-bit
wixmachine scopegithub.com · known platform- File name
- Flameshot-14.0.0-win64.msi
- SHA-256
- b3c38680c792410812e787d48ac1825c771fb044380d45789719b9e8373327ea
by flameshot-org · GPL-3.0
Powerful yet simple to use screenshot software.
These URLs are the ones flameshot-org declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what flameshot-org published. Delete it.
Windows · PowerShell
Get-FileHash "Flameshot-14.0.0-win64.msi" -Algorithm SHA256macOS · Linux
shasum -a 256 "Flameshot-14.0.0-win64.msi"Expected output
b3c38680c792410812e787d48ac1825c771fb044380d45789719b9e8373327ea
Got a different hash, or one you cannot place? Paste it into the hash checker and it will tell you which program and version it belongs to, past releases included.
This installer is an MSI package, so it takes the standard Windows Installer switches. That is a property of MSI itself rather than something the publisher declared.
64-bit · machine scope · MSI convention
msiexec /i "Flameshot-14.0.0-win64.msi" /qn /norestartRun it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
The macOS build as Homebrew declares it, with the same treatment as the Windows side: the publisher's own URL and a hash to check it against.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 1 of 1 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 1 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 1 of 1 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 2 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | GPL-3.0A declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions Flameshot registers itself to handle.
The installer comes from a recognised distribution platform rather than flameshot-org's own domain. That is normal for this kind of software and not a red flag by itself.
The installer on this page comes with the SHA-256 flameshot-org declared, so you do not have to take our word for it: hash the file you downloaded and compare.
What this does not tell you is whether the software itself is any good, or whether you want what it does once installed. A publisher can ship something you would rather not run and the download is still authentic. We answer the question we can measure and leave the other one to you.
If Windows says “Windows protected your PC” when you run it, that is SmartScreen reporting reputation, not a malware verdict — it shows up on perfectly legitimate software from small publishers and on releases that are simply new. The reverse matters more: no warning does not mean the file was checked.
How the 95/100 score is calculated · why the source matters more than the reputation
Windows ships with a package manager, and this program is in it. The identifier below is the one Microsoft's repository uses, which is also where the download URL and hash on this page come from.
Install
winget install --id Flameshot.Flameshot --exactUpgrade later
winget upgrade --id Flameshot.FlameshotWhy --exact: without it winget matches on name as well as identifier, and a search that returns more than one package makes it stop and ask rather than install. Pinning the identifier is what makes the command safe to put in a script.
Not installing anything, or getting an error back? The commands that actually come up covers upgrading everything at once, what --include-unknown is for, and why winget can be missing from a machine that should have it.
The version history of Flameshot, each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
37CA5916450FAB003FB3C64EACD01D103D11D122C30BADE6AF144D4B0874DF66
48A977F2D290D01EE37CDC9C4330DD06784277CB44EBD2741DFEC0DB192C279A
7EABB69576F276FD90B7B012BD8C2CF498042BEE78E6B1A7F4436C9A9D0F3E7C
2914E1CC9BBBA68BBED2B4A62A8B39F91B82EB011EF90618C3F3DB2EB1B8DB3B
2190FFE6A9D935D26CBF1BF2BE86FC9D1CB49AA6A068C0C5F9D502E1816ED352
E4559E32213FFA2E60533A02C5845AEBFE110D5C8D8592739C6A6D202928FABF
F68777FC1B768A2058B9717BE34BF9A9D4D6F386B8DF9651FA6362CD5A07C9AF
EE24A8E3E68D7D03539244C5EC0CC900BC5AAA745AF8FE149EAD3DE8C422194B
B2705F19078BF515151CA1AAA2F71D2AE1316CC74CCEEB6BF197AA2650AB4170
9F93815BC095DA98F7A9416BD2D3E18E5AC0AB916CDB09A800ED76146F47C5FA
64C0381189BF0434FB7D1E10E5B14E4AE8D1ED0A12F125464B6E51BCA3AE5205
91CB939D440D8A00ACDBB995177E88ACBBB0609E69C2ABA471883D11A0A3AC67
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published.
Every Flameshot version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.
Matched on the categories flameshot-org and others declare in their own manifests, so the grouping is theirs rather than ours. Each one has its official URL and hash on the same terms as this page.
Not related to Flameshot — just other entries, each with its own official URL and published hash.