So there's KeepassXC, keepass2Android, keepass, and keepassdx, and probdbly others. I can't find reliable source of meaningful comparison data.

Any suggestions? Looks like keepass XC is "best"? I have no need for more than basics including attached files.

I've been running about the same: XC on the desktop -- comes with debian distro I guess -- keepass2android and also KPass on the phone.

There doesn't seem to be much difference between them I can discern.

Have been looking at adjusting my practices and, sadly, browser, maybe vivaldi, and handling passwords differently.

I guess I'm mostly looking for outliers -- good or bad ("DONT USE KPASSLEAK") etc. There's yet another "keypass" on f-droid, but otherwise, it's all google play.

Things are not good.

@tomjennings

The only distinction I would make re: XC on the desktop: If it matters to you, the version in the Debian repo(stable) is about two versions behind the current release.

I decided it was worth it, for me, to keep it up to date. Initially, I used the AppImage and eventually migrated to the FlatPak installation for less manual futzing. It's the only app I use with FlatPak.
Otherwise, IIRC it will take ~15 days for the latest version to reach stable. Just something to consider depending on your personal risk/threat evaluation.
Hope that helps rather than frustrates. 😆