The websites allow for a vulnerability in third party code to expose you. Keepass, even if it has a vulnerability, can't be exploited remotely since the database is stored only locally.
The websites are in the browser and encourage browser extensions. Browsers suck for security... that's a massive attack surface and they are, by their nature, integrated with the network. Keepass is a dedicated application with a tiny surface that barely communicates with the internet at all and has no need to. A whole class of attacks miss it.
Keepass is leaps and bounds more secure.