New bugfix release: #KeePassXC 2.7.12. More information and full changelog at keepassxc.org/blog/2026-03...
@keepassxc.org
KeePassXC password manager – https://keepassxc.org GitHub: https://github.com/keepassxreboot/keepassxc Snapshot builds: https://snapshot.keepassxc.org/ Mastodon: https://fosstodon.org/@keepassxc Team email PGP key: 2FB8 CA9C 105D 8D57 BB97 46BD
New bugfix release: #KeePassXC 2.7.12. More information and full changelog at keepassxc.org/blog/2026-03...
To everyone experience issues with KeePassXC-Browser on Edge at the moment: We are aware of that. It's caused by a browser engine bug that has already been rolled back in other Chromium-based browsers, but not Edge. Please be patient, downgrade, or use this workaround: github.com/keepassxrebo...
It's a test run. We'll evaluate how popular this actually is and whether it's worth the hassle. :-)
Due to repeated request, we now support SEPA transfer and Wero as new donation methods. Want to support us? Go to keepassxc.org/donate/ 💰
Doing that on private channels and we’re already engaging a lot with people who mention us here and on other platforms (especially Mastodon where most of our followers are). Another full feed would be too much, sorry. And following random people without actually “following” them seems also wrong.
🥳
Maybe, maybe, maybe…?
Worauf sollte man bei einem guten Passwortmanager achten?
• Verwendung eines Masterpassworts für den Zugang zum Passwortmanager • Automatische Sperre nach Zeitüberschreitung, • Passwortmanager unterstützt die Verwaltung von Zwei-Faktor-Authentisierungsinformationen • Metadaten: Nicht nur das Passwort, auch Benutzenamen oder zugehörige Webseiten sollten verschlüsselt sein • Wiederherstellungsoption, falls das Masterpasswort vergessen wird
Laut einer technischen Untersuchung von zehn Passwortmanagern, die wir mit dem FZI Forschungszentrum Informatik & der Verbraucherzentrale durchgeführt haben, kam heraus: Es gibt durchaus Unterschiede in den getesteten Produkten! Zur Pressemitteilung: 👉️ www.bsi.bund.de/dok/1188780
Based on early feedback provided from the BSI (and similar request in the past), KeePassXC 2.7.11 (released two weeks ago) changed the default auto-lock setting after inactivity to "on" with a timeout of 15 minutes. Go to settings -> Security in case you want to restore the previous behaviour.
We're also mentioned explicitly for being particularly privacy-friendly.
The full report (in German) can be found at www.bsi.bund.de/SharedDocs/D... and www.verbraucherzentrale.nrw/wissen/digit... 2/2
Earlier this year, the German BSI together with the Consumer Advice Centre NRW performed a review of 10 popular password managers. What can we say? We're happy to be one of only few to receive a very positive review without major security concerns. 1/2
🎊 Big news! KeePassXC @keepassxc.org reached 25,000 stars on GitHub! High five! 🙌
Cross-platform, secure password manager
Please open a bug report on GitHub about that.
Our default on Windows is Consolas, not Courier. Markdown in the notes field is an open issue and will be added in a future version: github.com/keepassxrebo...
The full report of the CSPN audit performed by Synacktiv on behalf of ANSSI is now available on our website. If you ever wanted to know how KeePassXC works under the hood, it should make for an interesting read with many annotated code examples. keepassxc.org/audits/#cspn...
New macOS DMG and AppImage builds have been posted as 2.7.11-1.
New macOS DMG and AppImage builds have been posted as 2.7.11-1, which fix code signing and packaging issues.
Update: There's an issue with the code signature on macOS, which prevents users from using the browser extension and the CLI tool. We're looking into that and will post a fix later today. github.com/keepassxrebo...
On 17 November 2025, KeePassXC (Version 2.7.9 for Windows 10) has been awarded a security Visa by the French National Cybersecurity Agency (ANSSI) for a First-level Security Certification (CSPN) with report No. ANSSI-CSPN-2025/16.
The most notable new features are: support for more file types in the inline attachment viewer, the ability to edit text file attachments, a new database merge confirmation dialog, support for groups in KeeShare, and an option for automatically generating passwords in new entries.
🎉 We're very happy to announce our new release KeePassXC 2.7.11 and... *drumroll* that the KeePassXC version 2.7.9 has been awarded a CSPN Security Visa by the French National Cybersecurity Agency (ANSSI). 🎉❤️
See our blog post for more information: keepassxc.org/blog/2025-11... #VisaSecu #KeePassXC
I hope having this here is enough. This doesn’t look like a large scheme to me at the moment, but still concerning.
Medium post with fake coin.
Another Medium post with fake coin.
Fake airdrop website.
🚨Careful! There seems to be a series of Medium posts advertising a new $KEEPASSXC crypto coin with links to fake airdrop websites. THIS IS NOT REAL! Stay away! We don’t offer crypto coins and we have not the slightest desire to do so.
We wrote up a blog post detailing our development and quality assurance workflow. We describe how new contributions are merged into the code base, and we address the change to our policy regarding AI-assisted code submissions and the concerns raised about it. keepassxc.org/blog/2025-11...
A) Thanks for the realisation.
B) You shouldn’t trust us anyway. We’re random dudes from the internet. We have some reputation, but that’s it. Feel free to review our code yourself or follow our development process on GitHub. Whether or not we use LLMs should be irrelevant to your assessment.
Thanks for actually reading our argument. You can make a million cases for why LLMs, tech bros, the AI bubble etc. are societal and environmental problems and you’d be preaching to the choir here. But making a fundamental security issue out of it when it’s objectively not is a weak argument.
Talking about us now instead of with us. Great. Also see previous answer. bsky.app/profile/keep...
And?
We encourage you to become educated on our process and policies: github.com/keepassxrebo...
We’re doing all we can to prevent vulnerabilities, but a blanket ban of AI code is not a rational part of that. You can make a moral argument if you like, but not a security argument.