64-bit
wixmachine scopegithub.com · known platform- File name
- KeePassXC-2.7.12-Win64.msi
- SHA-256
- feee096c1d5d0d7bb7b36b18174818f7bac889be7668c550ff0e5ef9206ea9a5
by KeePassXC Team · GPL-2.0-or-later
KeePassXC is a cross-platform community-driven port of the Windows application “Keepass Password Safe”.
These URLs are the ones KeePassXC Team declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what KeePassXC Team published. Delete it.
Windows · PowerShell
Get-FileHash "KeePassXC-2.7.12-Win64.msi" -Algorithm SHA256macOS · Linux
shasum -a 256 "KeePassXC-2.7.12-Win64.msi"Expected output
feee096c1d5d0d7bb7b36b18174818f7bac889be7668c550ff0e5ef9206ea9a5
Got a different hash, or one you cannot place? Paste it into the hash checker and it will tell you which program and version it belongs to, past releases included.
This installer is an MSI package, so it takes the standard Windows Installer switches. That is a property of MSI itself rather than something the publisher declared.
64-bit · machine scope · MSI convention
msiexec /i "KeePassXC-2.7.12-Win64.msi" /qn /norestartRun it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
The macOS build as Homebrew declares it, with the same treatment as the Windows side: the publisher's own URL and a hash to check it against.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 1 of 1 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 1 on a recognised distribution platformThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 29.8 / 35 |
| Served over HTTPS | 1 of 1 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 5 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | GPL-2.0-or-laterA declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions KeePassXC registers itself to handle.
The installer comes from a recognised distribution platform rather than KeePassXC Team's own domain. That is normal for this kind of software and not a red flag by itself.
The installer on this page comes with the SHA-256 KeePassXC Team declared, so you do not have to take our word for it: hash the file you downloaded and compare.
What this does not tell you is whether the software itself is any good, or whether you want what it does once installed. A publisher can ship something you would rather not run and the download is still authentic. We answer the question we can measure and leave the other one to you.
If Windows says “Windows protected your PC” when you run it, that is SmartScreen reporting reputation, not a malware verdict — it shows up on perfectly legitimate software from small publishers and on releases that are simply new. The reverse matters more: no warning does not mean the file was checked.
How the 95/100 score is calculated · why the source matters more than the reputation
Windows ships with a package manager, and this program is in it. The identifier below is the one Microsoft's repository uses, which is also where the download URL and hash on this page come from.
Install
winget install --id KeePassXCTeam.KeePassXC --exactUpgrade later
winget upgrade --id KeePassXCTeam.KeePassXCWhy --exact: without it winget matches on name as well as identifier, and a search that returns more than one package makes it stop and ask rather than install. Pinning the identifier is what makes the command safe to put in a script.
Not installing anything, or getting an error back? The commands that actually come up covers upgrading everything at once, what --include-unknown is for, and why winget can be missing from a machine that should have it.
The version history of KeePassXC, each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
74ABEA9E12282CC2B0FEB51EBC6DB65299EB4EF0086E89CFAD8DCAAFC94A6F67
57781A64392D55C950FE734D084B500B836EF5A8029995AE4DFD8D911ABA4B44
3B544343CE369377E54A3A6AC7A023B3C202AC034EEA6E6886BB8185E95B6A49
D940DA0D5F009A3F9FA9E182ACAA292C239A87066FBB7D37E6DFEDE1AAB53982
9C3DAB957DB0F769C4E67BFDF4F0134A65ECFA65C5569718A36AA88E649158CD
EFAF26903E0A6088BB0AB4E4F56F067D36A54D90F0402E9C1BC9EF46551E2675
93E36894C81181FB2200DE57E0592836E5DCB6124F776DB44AC185ADD6F90BD6
CA614EAD325513480378F6B55A570C05ED0570E199FEA63230985E9B15B59EDE
CEFD32F45A5D0A934A92486E70936F3FCE9FBA142FA06B2755C9C5465846850A
A737DD49A49A3C4B5FEADCC4FC60B7B039155D68C6EA68779F50431E8BD9BB37
9474B9AFBA75043886D0E02E62AE17B9433B9AD0777023A2D753B00C418A9B86
41AB0337BC630FE7C0F91B89E3FD868E75BA8C10E4BC6011AA5799F1A0A738E4
4B48F83DD63D9388C8D982037A671832E72767DFC296FF5B91D2E76049095FED
037722ADD4AC4DA52ED5DF43640B990EF4123ADA185DA73835DC7C636AE876F7
970E7C8214B0B71DDD0C9845175492D88363559569ED14EA7C37D2DDBE6A2375
5912AA09D1FFC35E12C6454AD156940F6440A2B9874E948C7315E79E84E709C0
73744686AF131E99A3BEC6FE28D4944834F9F81A99A7790C386FE5A75B144B64
4B7EE425400007F61783FC1D82A822F7CA79472CAF9308D1712411FACC5C6F3A
3B95A44ECAC25DF638323C7B75789EB14497DB50D25B67C90B170C2BA4B5FC85
2761465EBD9A9A02A714F1D27EE7B0B5965DB1A3D4057EA4138344C7F66EA9CB
9C3924B39773B4DD15D52D97CDF5D66117259742BBE753C84207EB8A82BAB5FB
01BF1B593EFC4A9B92E0CA7148414F6D4F0E63521AEFA64D1F8CAA0327D35E91
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published.
Every KeePassXC version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.
Matched on the categories KeePassXC Team and others declare in their own manifests, so the grouping is theirs rather than ours. Each one has its official URL and hash on the same terms as this page.
Not related to KeePassXC — just other entries, each with its own official URL and published hash.