Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have existed for SSL certificates the other day.
Unfortunately some sites require you to "log in with your ... credentials" rather than doing SSO. But you TOFU those, too, once you've verified they're legit.
Happy Bitwarden user here: the software is all Free, but I trust the company to run their servers securely more than I trust myself to, so I pay them to do so. Extra benefit: if I lose all my infrastructure, I haven't lost my passwords.