I dunno, I think Debian are being wise here.
A while ago KeePassXC published a glowing audit report, but the report just ignored the scary stuff -- i.e. the things being disabled here like browser integration. I took a quick look, and thought the design could use some work -- but when I tried to discuss it they were very dismissive.
I did file a bug for one of the vulnerabilities we discussed, but I don't think they changed anything and didn't seem interested.