Makes me think if survivorship bias (or similar) applies here. While it's not fun to see LP having a lot of incidents in its history, maybe those could be viewed as something that has made LP stronger over the years?
I'd be more worried about a password manager that has never seen any security incidents - is it because there really aren't any, or that they haven't been caugh? Surely a security incident on a password manager serves as a major motivation to harden shit up?