> most people should be using nothing but certbot and mkcert
Most people likely don't know (and don't have to) about any of those, possibly most tech workers could indeed get away with just those two (though openssl has useful functionality other than key/certificate generation, but I guess one can avoid using that too), yet even mildly advanced usage would require more advanced tools. Actually certbot is primarily an ACME client, so not easily interchangeable with/comparable to openssl, while mkcert only covers one very specific use case: probably common in that middle group, but I don't quite see why it needs a separate program: a basic shell script (or an alias) would achieve that.
> You want tools designed to do one thing well, not one tool that offers a thin layer of getopt() over a low-level cryptography API.
Well, it offers that thin layer rather well! Seriously though, there's likely some middle ground between mkcert's lack of options and openssl's functionality covering a lot of other bits in addition to X.509 certificates. Though then again, you can consider `openssl x509` as basically a separate program, with its own man page and options -- and then it focuses on one thing, providing a rather complete functionality.