Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…
I agree with everything you've written here, but while all good points, they're really more about convenience -- not trust. _Why_ do you trust Bitwarden? I also use BW btw, but I don't have a good reason as to why they're trustworthy, and will probably run my own server someday.
And the irony is that the one website I can't trust my password manager to protect me from phishing attacks on is the password manager's own web interface. So I always want to log in with one of the non-web clients, and only trust the web vault if I reached it via a known-good link (like the one in the settings panel of the browser addon and mobile apps).