I use bitwarden as my password manager. Out of paranoia, I have been logging into Bitwarden only while an empty tab is open in case some random website is able to access my keystrokes while I use the plugin. I am a web developer, but I wasn't actually able to find information about whether this is a real risk or not last year when I began doing it. Can anybody clarify?
If you really want to be safe, you should use the standalone desktop apps and skip the browser extension altogether. Doing that empty tab thing probably doesn't protect you from anything.