This hasn’t been shown to be true in any meaningful way.
At least I remember reading that that was why the Bitwarden extension is so safe. It doesn’t do anything until I press a button.
The downside of not using a password manager is that users enter (or paste) their passwords without any robust domain validation. In phishing scenarios, a missing auto fill prompt is likely to be enough to encourage a pause and think.