You don't need to. You need to trust Lastpass's design.
A Lastpass database is an AES-256 encrypted blob, encrypted using a "slow" hash of your master password (PBKDF2, rounds are configurable). Lastpass don't know your password. When they authenticate you they test to see if your database is decryptable with the password you entered (after it is hashed). If you set 2F then they won't even allow attempts until 2F is satisfied (Google Authenticator is free).
Lastpass's biggest weakness is also applicable to this theoretical OpenSource alternative: Javascript. Javascript is delivered from Lastpass (for the browser extension) and after you decrypt your password database, that JS has full access to it. If a "bad guy" is able to inject evil JS between you and them, then they could trivially steal already decrypted passwords.
As I said, this weakness has nothing to do with Lastpass, it would equally apply to all password managers which integrate into the browser with an extension. In effect you've exchanged convenience for security. And you can already read the Lastpass browser extension's source code, being more open source doesn't make you immune from this issue.
So you can choose to trust Lastpass, or not, but the design is sound. Slapping the words "open source" onto something won't mitigate any of LastPass's inherent design issues, and you'd still want to follow a similar design since it is a good compromise between security and convenience. Coming up with a superior design that doesn't sacrifice convenience would be awesome, but it is a hard problem...