I agree, in the sense that one successful attack on the supposed centralized database containing all user credentials would have a high ROI.
But it also applies to local password managers. If 20 million people use the same password manager and I have an exploit for it, if I'm in the business of stealing data I'm likely to find a use for my exploit.
Someone is going to exploit my local password manager remotely?
I don't know - who are you?
Even if you are not an especially valuable target, malware is pretty widespread. It steals credit card numbers and other data; if the attacker had a hack for a popular password manager, why wouldn't they go for it?
It may be unlikely, but it's still putting all eggs in one basket. Just one failure, and you are truly fucked.
If you have an eidetic memory and can remember 20 digit random passwords for every service after securely generating them then keepassx increases your risk.
If however you behave like a 'normal' user and use the same one or three passwords on everything I'd estimated keepassx improves your security.
The truth is that I don't give a fuck about losing 90% of accounts I use (and I guess I'm not the only one). Many of them I could even give you myself as a birthday present. Using password manager as a rule of thumb would imply that these accounts are as important as the most important ones. Which is nonsense. Even if we discard all the disposable accounts, I still doubt that losing your twitter would hit you nearly as hard as losing your main email account or bank account.
However, exposing that all these trash accounts are mine might make me feel uncomfortable.
If that makes sense, then we must actually stop using the rule "password managers FTW" and start using the rule "consider how important is every given account to you, and treat it accordingly, chosing between several kdbx files". Which is much more complicated rule, obviously. I would even say it creates much higher mental load than remembering several sufficiently complicated passwords.