Pass was built by Jason Donenfield (zx2c4) who is competent enough to have also built WireGuard and survived the resulting years of uh, review by the Linux kernel team.
The parts of pass I've actually read (which is admittedly not all of it) are designed in a way that feels like the author understands both the large problem (password management) and lots of little implementation details to get there correctly.
One thing I particularly like is how pass gets random passwords. Unlike this tool 'pass' will generate you a strong random password, optionally constrained however you please. The insight is that the CSPRNG is cheap, so you shouldn't put any work into conserving random numbers by doing fancy algorithmic stuff. Instead pass consumes bytes from the CSPRNG (/dev/urandom) and just discards all the ones that aren't allowed in your password. So e.g. if you ask for a numeric password and 'pass' reads the byte 0x8F from the CSPRNG, it doesn't try to massage that into a numeral, it just discards it and fetches another byte until it gets one in the range 0x30 to 0x39. This inefficiency is actually totally fine and makes it easy to verify that the code is correct, which is much more important than slightly reducing the workload of the CSPRNG.
tl;dr I would (and do) trust pass but not this program.