Earlier quoted context omitted.
How does this address the point of the article? Which is that you should use the browser's builtin password manager and not a third party manager that injects user scripts into all websites and break the sandbox model?
The point is that while yes, many 3rd party password managers have issues, the overwhelming majority of attacks are not against password managers but against reused passwords - so honestly either the 1st or 3rd party choice is a win over using neither.
1) not use any manager => bad
2) use a 3rd party => pretty crap as the article says
3) use a built-in => great
Why would you ever use 2? This is almost as bad as Bitcoin, which not only solves nothing but also destroys a ton of energy.
I have never used a manager except for the builtins. And I would have never expected them (prior to reading this article) to be such utterly junk solutions to just inject additional code into the website itself. I thought there's a dedicated browser API or something.