32-bit
innomachine scopesourceforge.net · known platform- File name
- download
- SHA-256
- 9923a8b228fe3d8fbe46979991f45d7e0d63f649766596da191eb879b293d38d
- Product code
- KeePassPasswordSafe2_is1
by Dominik Reichl · GPL-2.0
KeePass, the free, open source, light-weight and easy-to-use password manager.
These URLs are the ones Dominik Reichl declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what Dominik Reichl published. Delete it.
Windows · PowerShell
Get-FileHash "download" -Algorithm SHA256macOS · Linux
shasum -a 256 "download"Expected output
9923a8b228fe3d8fbe46979991f45d7e0d63f649766596da191eb879b293d38d
This installer is an MSI package, so it takes the standard Windows Installer switches. That is a property of MSI itself rather than something the publisher declared.
32-bit · machine scope · MSI convention
msiexec /i "download" /qn /norestartRun it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
Silent install commands for every program we index · silent uninstall
Every guide on this tells you to hunt for the product code with Get-WmiObject or in the registry. You do not need to: it is published in the installer manifest, and it is printed below.
Product code · 32-bit, 64-bit, ARM64
{33F0E718-1110-4F95-A59B-230A62C02DE5}
Uninstall, with the usual prompts
msiexec /x {33F0E718-1110-4F95-A59B-230A62C02DE5}Silent, for deployment
msiexec /x {33F0E718-1110-4F95-A59B-230A62C02DE5} /qn /norestartThe codes above belong to KeePass 2.61.1, the version in our index. If you have an older release installed, its code is different and this command will report that the product is not installed. In that case run Get-Package -Name "KeePass*" in PowerShell to read the code of what you actually have.
This removes the program as the publisher packaged it. Settings and files created after installation, typically under AppData, are deliberately left behind by the uninstaller and have to be deleted by hand if you want them gone.
Reinstalling and hitting error 1638? That is this same product code, and the command above is the fix.
Product codes for every program we index, with the msiexec switches and how to read the code off your own machine.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 6 of 6 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 6 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 6 of 6 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 4 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | GPL-2.0A declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions KeePass registers itself to handle.
The version history of KeePass, each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
0CAD96C498017546065B5885E501B4A104EE8304506126310FD825D01DCAB284
C7D1B38C6BBC953E857AC6197D01ADFD66FF50824B65D9ED470FE8DB0113C6CA
DDBFC88ED78D2A5E23046A69B27B4C9F9989891BE9216E68D58797E8236C413C
5D9D4AC736BCBEE5B7DFF10BF0F9151C633C019F9C1A4B1E617BF70A5B901CB3
67CDDF931CD04138EE9207651CB3A539C187099A9579C8FEAEC2647426A1FE67
2B659E93AB28AFD7418CF89BBF998F36716BCF8A4C2EEDBC53AA1D6FBCC7BB79
D1FB8A8E9837FD91033F930B52FA2F2B0A83CD2A49FBC00BA98153911B0A7715
16B8B975DB5198E4292DF0841AA66F8B7137D0B65FFE33ACD19972F26A4D0E6B
96B4FCA5E148B44AF908C5B0D98DAA526CB4106C68950EAC1C2CE3E40EB44C9C
94058CEC5B0374B884C4EE1540E1E62EACA9D87AFC43DE4B9F5A655554CB94D7
EA53F7F944FADA950CD7BB154DEB078123A357B7BC5E2484851762B3552EB48B
85BCF6A0E8E2B5CE0817329736AD1794541C39A2928815EB9061C351C3B2E535
92529DC0E6449ECA21688601020455505462819217B8E8D51F6E7B1DD05A69EF
AF7C504B2B16F6F664B5154921B7F8AA3F44FA593D90F96F858A66F6A4C3F4BC
37C2488E0D29E2ADE03827DD3D9C4C4563C4506B98BA24BB3EF1981FDD6D765D
2CECB803B8230DF7D65FA0534CF80E5F0216D6644FFD0CA6BBCE6008F996B89F
BDE840661BB08E10E12EDFD49F77E2620C6129BD616046E4DA50872429C771FD
0FF5CFC84803DFBAD478AC85A5894395EF35F04A9DC59C1BB836C0D67CE6176A
762D06CF1394CB9F0680EE7E3757948D1E59668B0E15C3684F52F44BCC8BE428
067727CAA782F53F6232F8F59BC945384FCE98817B014300039B28487C06A5CD
7FFB2815B26B2AFE328E2D59741C63C890963213B0DEA337B27C8139FD388361
BBE39EB55F720A0549B4457B73991F3C42F6610DDE86A00D94F5CFB87472DF07
3EADEF4AC19E279878F2E48FEBF6FD830A66AFFEBFB2B59B8F36FC0A03BE0190
DA403BC2E91132D1C1E0C49F585441E4CD430C8195CA8AF38ADC2EA300DE52CB
C476710AF1DFDA272ACC18D97C48A9B31F4DD2CEDD6A0F12CEB178E83E82CC87
6FB6A206C2C68514DAD5048E82B28105FC7FA5A967033C6D402AEACFE09A974A
B2C469E6B094DB1FC2CBB3143457EC4948E4ADDAEAA633E18B7B8904C09B98D3
A68704E639D75BAB76CF2BEEC883E93981F454176FA355758AFC9829037F10FA
BDFA1B1360F6C99A98EBB1CEB0E43A5C23FEABC8194F7EA00128C7D69AA8E4FF
17716D7C78A5A377FD31872D7C6E1B436782B00AA5AD1BAEA1A59E53F5EF8D63
284847FDD65BCB272AD773CC25720A18E91DAB5E66EAA790B2500D477C3895F9
6659E447292B05E43841F94686BE58F34C5FA785F3A68816F9AEE60A63EF3E82
3EB2723AE5363C8400B494A5C2BB24D911E622ECBC15B20AAA32526A7BB45E42
F01157E970AD1D230BC99E19ADF9C79F8A97EBE847F8BFDE5D2D076A062B2A68
9058CC9D44129E8C2C902E21F8678974B789ECD8F9D6ADD81C98FBEAF9794E23
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published. Older releases than these are still searchable by hash on the hash checker.
Every KeePass version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.