These are pen-tests and black-box security audits. While they're definitely better than nothing, and they would show that their security is better than LastPass', the code was never audited.
I am in no way familiar with these kinds of reports, but does this not mean that (at least parts of) the source code was audited?