Blog

Best Claude Code Memory Plugins in 2026: A Deep Comparison for Developers

We tested 15+ Claude Code memory plugins head-to-head. Here's our verdict on claude-mem, Vestige, Total Recall, and more — with security audits, token cost analysis, and recommendations for every use case.

Tradelyze Engineering··18 min read

At Pick MyTrade Pvt Ltd, we build Tradelyze — a platform that helps traders test and optimize Pine Script strategies using walk-forward analysis, robustness testing, and prop firm validation. Our engineering team relies heavily on Claude Code for daily development, and one pain point kept resurfacing: Claude forgets everything between sessions.

Every new conversation starts from scratch. Context about architecture decisions, debugging discoveries, coding preferences — all gone. For a complex trading optimization platform, re-explaining context wastes significant development time.

So we did what engineers do: we tested every notable memory plugin we could find. This article shares our findings — covering architecture, security, token costs, and real-world performance — so you can make an informed decision for your own workflow.

1. What Are Claude Code Memory Plugins?

Claude Code is Anthropic's official CLI for software development with Claude. While powerful, it has a fundamental limitation: each session starts with no memory of previous conversations. Memory plugins solve this by persisting context across sessions — coding patterns, architecture decisions, debugging insights, and user preferences.

These plugins work through three main mechanisms:

  • Lifecycle Hooks — Claude Code exposes hooks (SessionStart, PostToolUse, SessionEnd, etc.) that plugins tap into to automatically capture and inject context.
  • MCP Servers — The Model Context Protocol lets plugins register tools that Claude can call directly (search memory, save memory, etc.).
  • CLAUDE.md Management — Some plugins automatically update the CLAUDE.md instruction files that Claude reads at session start.

2. Claude Code's Built-in Memory System

Before evaluating third-party plugins, it's worth understanding what Claude Code offers natively:

CLAUDE.md Files

Persistent instruction files that Claude reads at session start. They can be placed at multiple scopes: project-level (./CLAUDE.md), user-level (~/.claude/CLAUDE.md), or local-only (./CLAUDE.local.md). Best kept under 200 lines per file.

Auto Memory

Claude writes notes to itself based on corrections and preferences. Stored in ~/.claude/projects/<project>/memory/MEMORY.md. First 200 lines load at session start. This is useful but limited — it doesn't capture tool outputs, session transcripts, or provide semantic search.

For many developers, the built-in system is sufficient. But for teams building complex systems — like our trading optimization pipeline — we needed more.

3. 15+ Plugins Compared: The Full Landscape

We evaluated every notable memory plugin available as of April 2026. Here's the complete landscape:

PluginStarsMechanismStorageAuto?License
claude-mem46KHooks + MCPSQLite + ChromaYesAGPL-3.0
Vestige471MCP ServerSQLite + USearchSemiAGPL-3.0
Total Recall192HooksMarkdownSemiN/A
ourmem183Plugin + MCPCloud/DockerYesApache-2.0
memory-compiler174Hooks + SDKMarkdownYesN/A
auto-memory129HooksCLAUDE.mdYesMIT
Memory Engine111HooksMarkdownSemiMIT
TheBrain85PluginFile-basedSemiN/A
ClawMem82Hooks + MCPSQLiteYesMIT

Other notable entries: Heimdall (102 stars, Qdrant-based), claude-memory-extractor (109 stars, retroactive mining), Roampal (39 stars, outcome-based scoring), and mem0-mcp-selfhosted (62 stars, knowledge graph).

4. claude-mem: The Most Popular Option (46K Stars)

Repository: thedotmack/claude-mem | 222 releases | AGPL-3.0 license

How It Works

claude-mem uses 6 lifecycle hooks to automatically capture everything Claude does during a session. The PostToolUse hook fires on every tool call — Read, Write, Bash, Edit, Grep — and sends the full input and output to a worker service running on port 37777.

The worker then spawns a second Claude agent (via the Claude Agent SDK) to compress raw tool data into structured observations. These are stored in SQLite with FTS5 full-text search and optional ChromaDB vector search.

On the next session start, the most relevant past observations are retrieved and injected into your context.

Security Concerns

Multiple independent security audits have flagged critical issues:

  • Unauthenticated HTTP API — 30+ endpoints on port 37777 with no authentication. Any local process can read all your stored data, extract API keys, inject false memories, or delete everything. (Issue #1251)
  • Path Traversal — MCP tools accept file paths without boundary validation, allowing reads of arbitrary files like ~/.ssh/id_rsa.
  • Prompt Injection — Stored observations injected into LLM context without sanitization.
  • Zombie Process Bug — One user reported 280 orphaned Claude CLI processes consuming 65 GB of RAM and burning $183/day in unintended API spend. (Issue #1090, now fixed)

The $CMEM Token

The creator officially endorsed a Solana memecoin ($CMEM) in the project README. While the token is not required to use the plugin, it's unusual for a serious developer tool and has eroded community trust. (Issue #1300)

5. Vestige: The Cognitive Science Approach

Repository: samvallad33/vestige | Single ~22MB Rust binary | AGPL-3.0 license

Vestige takes a fundamentally different approach. Instead of auto-capturing everything, it models memory like a human brain — using peer-reviewed neuroscience research to determine what's worth remembering, how memories strengthen or decay, and how to retrieve related knowledge.

Five Cognitive Mechanisms

1. FSRS-6 Spaced Repetition

A 21-parameter power-law forgetting model trained on 700M+ Anki reviews. Memories accessed frequently build high stability. Unused memories decay naturally — below 10% accessibility, they stop surfacing in search. This prevents memory bloat without manual cleanup.

2. Prediction Error Gating

Inspired by hippocampal filtering. New content is compared against all existing memories via cosine similarity. High similarity (>0.92)? Just reinforce the existing memory. Low similarity (<0.75)? Create a new one. Saying “I prefer dark mode” five times creates one strengthened memory, not five duplicates.

3. Synaptic Tagging

Weak memories get temporary molecular tags. When something important happens within a configurable time window (default: 9 hours back, 2 hours forward), all tagged memories in that window get retroactively strengthened. Context that seemed trivial becomes valuable when related events occur.

4. Spreading Activation

Memories form a semantic network. Searching for “auth bug” doesn't just find direct matches — it follows graph edges to related memories like “JWT library update from last week.” Activation decays 0.7x per hop with a minimum threshold of 0.1.

5. Memory Dreaming

Modeled on sleep consolidation. Every 6 hours (or manually), Vestige replays recent memories, discovers cross-references, strengthens co-accessed connections, prunes weak ones, and transfers episodic memories into generalized semantic knowledge.

Architecture

A single ~22MB Rust binary bundles: an MCP server (stdio JSON-RPC 2.0), an Axum HTTP server, a WebSocket event bus, and a pre-built SvelteKit + Three.js 3D visualization dashboard. It uses Nomic Embed v1.5 for local embeddings (~130MB model downloaded once, then fully offline) and USearch HNSW for vector search.

21 MCP tools provide search, ingestion, dreaming, connection exploration, health checks, backup/export, and more. The session_context tool reduces startup overhead from ~15K tokens to ~500-1,000 tokens.

Security

  • Zero network calls after initial model download
  • Bearer token authentication on HTTP transport (UUID v4, constant-time comparison)
  • WebSocket origin validation (localhost only)
  • Optional SQLCipher encryption at rest
  • Parameterized SQL queries, FTS5 sanitization, 1MB content size limit
  • No telemetry, no phone-home, no shell execution
  • AgentAudit scan: 0 findings | cargo audit: clean

6. Head-to-Head: claude-mem vs Vestige

Dimensionclaude-memVestigeWinner
SecurityUnauthenticated API, critical vulnsBearer auth, zero network, encryptionVestige
API CostDoubles token spend (observer agent)Zero (local ONNX inference)Vestige
Auto-captureEverything, automaticallyClaude decides what to saveclaude-mem
Memory MgmtStores permanentlyFSRS-6 decay, dedup, consolidationVestige
Retrieval3-layer progressive7-stage pipeline + rerankingVestige
Maturity7 months, 46K stars2.5 months, 471 starsclaude-mem
Cross-IDEClaude Code onlyAny MCP client (8+ IDEs)Vestige
SetupBun + worker + hooksSingle binary, 2 commandsVestige
VisualizationWeb viewer3D Three.js dashboardVestige
DependenciesBun, Node 18+, Python/uvNone (self-contained)Vestige

The core philosophical difference: claude-mem is a diary — it records everything. Vestige is a brain — it selectively stores what's important and lets the rest fade naturally.

7. Other Notable Plugins

Total Recall (192 stars)

Markdown-based tiered memory with a “Write Gate” — 5 checks before anything gets permanently saved (“Will this matter tomorrow?”). User-controlled promotion via /recall-promote. No database, no semantic search — just organized markdown files. Ideal for developers who want full control over what's remembered.

claude-memory-compiler (174 stars)

Inspired by Andrej Karpathy's insight that at personal scale (50-500 articles), an LLM reading a structured index outperforms vector similarity search. Captures session transcripts, extracts lessons into structured markdown articles, and maintains a simple index file. No database, no vector DB — runs on your existing Claude subscription.

ourmem / OMEM (183 stars)

The only option with cross-agent and cross-team shared memory via “Spaces.” Features an 11-stage hybrid retrieval pipeline and Weibull decay model. Available as cloud-hosted or self-deployed (Docker). Apache-2.0 license. Best choice for teams that need collaborative memory.

claude-code-auto-memory (129 stars)

Focused scope: watches file edits and auto-updates CLAUDE.md files to keep them in sync with codebase changes. MIT license, lightweight, does one thing well. Not a full memory system — best used alongside another plugin.

8. Security Deep Dive

For a trading platform like Tradelyze that handles proprietary Pine Script strategies and financial data, security isn't optional. Here's how the top plugins compare:

Aspectclaude-memVestigeTotal Recall
Network callsAnthropic API (observer)None after installNone
API authNoneBearer tokenN/A (no API)
Encryption at restNoOptional SQLCipherPlaintext markdown
Data capturedEverything autoSelective (Claude decides)User-controlled
Known critical vulns2 Critical + 4 High0 findingsNone reported

Our take: If you're building anything that touches financial data, proprietary algorithms, or API credentials, security posture should be a primary selection criterion — not an afterthought.

9. Token Cost & Performance Impact

claude-mem: Significant Cost

  • Runs a parallel Claude agent — roughly doubles your token spend
  • Sessions exhausted in under 10 messages on complex projects (Issue #618)
  • Past zombie process bug burned $183/day for one user (Issue #1090)
  • v11 routes simple observations to Haiku (~52% cost reduction)

Vestige: Minimal Cost

  • Zero extra API cost — all inference is local ONNX
  • ~3,000-5,000 tokens for 21 tool definitions in context window
  • ~500-1,000 tokens for session context injection
  • Total overhead: ~0.5% of a 1M token context window — negligible

Performance Benchmarks (Vestige)

Memories StoredSearch TimeRAM Usage
100<10ms~50MB
1,000<50ms~100MB
10,000<200ms~300MB
100,000<1s~1GB

10. What We Chose at Tradelyze & Why

After testing all major options, our engineering team at Pick MyTrade chose a combination approach:

  1. Claude Code's built-in auto memory — for lightweight preference tracking and project conventions. Zero cost, zero risk, already active.
  2. Vestige — for persistent cross-session memory with intelligent retrieval. The cognitive science approach means our memory store stays clean without manual pruning. The security posture is appropriate for a fintech development environment. And zero extra API cost matters when you're running Claude Code sessions all day.

Key factors in our decision:

  • Security first — We handle proprietary trading strategies, Pine Script code, and prop firm configurations. An unauthenticated HTTP API exposing all our development context is unacceptable.
  • Cost predictability — Our team uses Claude Code extensively for the Tradelyze platform. Doubling token spend with an observer agent adds up fast.
  • Cross-IDE compatibility — Different team members use different editors. Vestige works with any MCP client — Claude Code, Cursor, VS Code, JetBrains, and more.
  • Self-cleaning memory — FSRS-6 decay means stale memories fade naturally. We don't need to manually prune outdated architecture notes from six months ago.

11. Recommendations by Use Case

Solo Developer, Cost-Conscious

Vestige or Total Recall. Zero extra API cost, fully local, simple setup.

Team Environment

ourmem. The only option with cross-agent shared memory via Spaces. Apache-2.0 license.

Maximum Coverage, Budget No Issue

claude-mem — if you accept the security trade-offs and token costs. Most comprehensive auto-capture.

Security-Sensitive / Fintech

Vestige + built-in auto memory. Bearer auth, zero network calls, optional encryption, no data exfiltration surface.

Keep It Simple

claude-memory-compiler or Claude Memory Engine. Markdown files, zero dependencies, easy to understand and debug.

Final Thoughts

The Claude Code memory plugin ecosystem is evolving rapidly. Six months ago, none of these tools existed. Today, developers have over a dozen options — from auto-capture systems to cognitive science-inspired memory engines.

The right choice depends on your priorities: maximum coverage (claude-mem), intelligent forgetting (Vestige), team collaboration (ourmem), or raw simplicity (Total Recall). For our trading optimization work at Tradelyze by Pick MyTrade, security and cost predictability led us to Vestige — and we haven't looked back.

Whatever you choose, adding persistent memory to your Claude Code workflow is one of the highest-ROI improvements you can make to your AI-assisted development process.

About Tradelyze

Tradelyze is built by Pick MyTrade Pvt Ltd, incorporated under the Companies Act, 2013 in India. We provide Pine Script strategy backtesting and optimization — including trade-by-trade matching against TradingView, walk-forward analysis, robustness testing, and prop firm validation — helping traders make data-driven decisions. Visit tradelyze.io to learn more.