- Filezilla stores all sites username and passwords in clear text in a fixed location: %APPDATA%\fielzilla\sitemanager.xml
- Even if you do not use site manager to save your passwords, Filezilla saves all "quick connections" to a file "recentservers.xml", again with all username and passwords in clear text.
- A bug has been filed for Filezilla to encrypt the passwords with a master password over 3 years ago, yet no action has been taken.
Switch to "WinSCP", which is also open source, and allow you to encrypt all stored passwords with a master password.