That said, even PassWord safe has some issues. As the article points out, it computes an HMAC over the unencripted contents instead of over the encrypted ones. Encrypt-and-MAC isn't broken like MAC-then-encrypt but its still not as ideal as Encrypt-then-MAC.
https://www.dropbox.com/s/f4gpc7shjal1nta/Screenshot%202015-...
https://cseweb.ucsd.edu/~mihir/papers/oem.pdf
You generally have two options when it comes to authenticated encryption: use a specialized AEAD mode, in which the details of authentication are settled by the mode itself, or use "generic composition" --- encrypt securely, MAC securely, and safely combine the two operations. Specialized AEAD modes are preferable. But if you're going to do generic composition, the best current practice is encrypt-then-MAC.
Even if you encrypt-then-MAC, you can still forget to authenticate parameters (a good reason not to use generic composition). But if you MAC and then encrypt, you concede to attackers the ability to target the cipher's decryption operation directly with chosen-ciphertext attacks. Those attacks are powerful and have repeatedly broken TLS; they're also the most common form of attack on other cryptosystems (every padding oracle attack is a variant of them).
I wrote a bunch about this here:
http://sockpuppet.org/blog/2013/07/22/applied-practical-cryp...
http://www.cs.ox.ac.uk/publications/publication7166-abstract...
Under 28 Dec 2014 it mentions 0.95, but there is a 0.96 from 12 June of 2015 available at
http://sourceforge.net/projects/passwordsafe/files/Linux-BET...
"The OPVault format uses Encrypt-then-MAC for authenticated encryption with AES-CBC-256 for encryption and HMAC-SHA256 for Message Authentication. Key derivation uses PBKDF2-HMAC-SHA512"