> Except the password manager becomes a central point of failure. If someone gets your phone, opens your password manager, boom they have keys to the castle. Because let's be honest, the password manager is on the phone, and there's no way keyloggers or screenshot backdoors get on there, and there's no way someone isn't looking over your shoulder with the latest iPhone Pixel Galaxy supercamera across the room.
Password managers usually are either password-protected themselves or have biometrics, which suffice to deter random thieves. In fact, password managers are not going to show your password in the first place, they are going to silently fill in password prompts. The password cannot be clipboard-stolen, screen captured, or key logged. It is even more difficult to fish you (if the password manager doesn't detect the right program id/URL, it won't fill your password in -- unlike you).
If someone is looking over your shoulder with a supercamera he can get one password. If you are using a password manager, that's it. If you were using "an algorithm" to derive your passwords it is now possible he can now easily guess ALL your passwords. Most people aren't that good remembering good "algorithms" anyway. Maybe he needs to capture two passwords to do so?
Unless your algorithm is truly good, in which case you likely have to store it somewhere and that becomes your "password manager", which shares the same cons as a password manager itself. You are even at risk of your "algorithm" being guessed through a couple big password DB leaks, which are sadly ridiculous common, and this by itself puts you more at risk than worrying about supercameras.
I however don't have anything good to say re password managers that sync passwords over a centralized service, or worse, do so without proven E2EE.