Or host vaultwarden on your homeserver and access it only through wireguard/nebula self hosted VPN.
As for KeePassXC, last I checked it didn't even bother.
Professional companies that care about security (I do IT security consulting so that's the group I deal with the most) are not perfectly secure. I'd argue that it's less likely that a password database is abused when hosted on a random average-security system (assuming the person is not being targeted, like if you're not a public figure or have a stalker) than if you've got it hosted with some bigcorp that has a huge target painted on their back. Some are really good at security and others a bit less, but none are perfect, and scale dictates compromises between security and usability. Not everyone in the firm will be a security expert, and much as you try to isolate the vaults / source code / other security-relevant systems from them, they're how ransomware and other groups gain a foothold to work with.
I wouldn't trust my mom to set up a server secure enough for a password manager to be hosted on, but if you are comfortable around servers at all and follow normal guidelines, or use normal syncing software that is only encrypted to the server (so you pick and rely on a strong password for your vault file), you're more secure than when you use a third party and type that password into their website (even if, on a good day, the key stays local in your browser).
Let's quantify that. The default KDF that keepassx uses is iirc ~50ms seconds of computation on modern hardware. It might dynamically determine the KDF rounds based on your system, but it never updates it (hmm, is that a vuln as well?) so it'll be old either way. A GPU gets a ~thousand-fold speed-up compared to CPU for pbkdf2, so let's say 20k guesses per second per GPU (note: this is just a ballpark number). An attacker might have a dozen GPUs available and care to spend a month on your vault (does that sound like a fair upper bound? Tweak it for your personal threat model), which means they run through some log(20e3 guesses_per_second × 12 gpus × (3600×24×31) seconds)/log(2) ≃ 40 bits of entropy.
If you pick random words from a diceware-sized dictionary (7776 words), you need 4 random words to be secure (because log(7776⁴)/log(2)>40). If you pick random characters from a-z,A-Z,0-9, you need a 7-character randomly generated password (because log(62⁷)/log(2)>40).
Edit: it looks like KeepassX has stopped development and says to use KeepassXC now. Their source code has some mentions of Argon2id so this may be outdated advice! Your password/-phrase may be able to be shorter than this, but it'll be hard to quantify because all Argon2 crackers suck ("For Argon2, the fastest cracking software that I can find is a CPU implementation." I wrote two years ago in https://security.stackexchange.com/a/249384/10863).
It has some cool features too, like not injecting anything into pages until you activate it (so no performance cost or risk of breaking sites) being less reliant on perfect detection of fields when it is activated, etc.
Found the SPOF! But also, "AI"? And "we've been building" doesn't sound like it's production-ready yet. I don't know, lots of red flags here to me.