Earlier quoted context omitted.
> I believe the point the article is making is that any browser extension to auto fill is inherently insecure for architectural reasons. No, that is not what the article said. The article said that password managers that insert elements into the webpage are insecure. You don’t need need to do that to autofill passwords.
Can extensions auto fill without content scripts?
Just to be clear, when I say autofill I'm not suggesting that it fills in passwords with zero interaction, but when you're on a website that Bitwarden has a password for, it shows a little flag on the extension icon, and you can click on it to fill the password.