The problem that some people are missing is that on most mobile platforms there are not restrictions to the clipboard, and virtually any application which is installed on the device can use it.
If the mobile platform would've supported clipboard isolation, or the application could plug into a password manager directly to retrieve the credentials that would be a completely different story. An "acceptable" alternative would be to implement an indirect clipboard in which a trusted keyboard application can replay the string for a short duration but that's not going to happen either.
The funny thing about password managers is that people claim they use them because they can't remember a complex password, while that's might be true but it also means that the password they use for the PWM is not complex enough to be used for say online banking in their minds which makes the fact that they use a PWM a bit ironic.
Whats worse is that probably most people who use a PWM on a mobile device choose to have a PIN lock on it after supplying the initial PW which reduces the PW complexity even further.
If you want to use a PWM on a mobile device i strongly suggest get some BT/NFC token based solution, while it's not the most secure one it's several orders of magnitude more secure than using a PWM on the common mobile platforms today.
Also as far as PW complexity goes while it's true that having a password like Password123 isn't a good idea, having something that looks like this isn't $qE`ADYCI=5% much better. There is an old XKCD comic about it and it's some what true that most randomly generated passwords are hard to remember but technically easier for a computer to brute force than a strong pass phrase.
If we are talking about hash braking then for example the following password melonyogurtstrawberry will take 2402661779222536 years 160 days 4 hours 58 minutes and 56 seconds to break (5.388571461264625e+29 password combinations), while the password $qE`ADYCI=5% will take only 167777774 years 185 days 20 hours 22 minutes and 17 seconds 3.7628372639504774e+22 password combinations). Both calculations are for an unslated SHA1 at 7000 Kh/s, and while taking into account the charset of both passwords so lcasealpha only for the 1st one, a mixedcase alpha numeric + all symbols for the 2nd one.
So while it might not seem like 3-4 random words form a more complicated password they do. Now before you go into dictionary attacks and say common words are easy to generate for a computer generating a string like melonyogurtstrawberry takes just as much time as generating something like $qE`ADYCI=5%, and while it's true that you might take just the most common words in the English language and do all possible combinations you are still left with 99955939123250 combinations if you take the 7000 most common words and use a 4 word pass phrase. And considering that most people have a vocabulary much greater than that with access to common "pop culture" words which are not part of the official English language the number of potential combinations is much much greater than that (which is good enough to begin with).
So yeah while it might not be popular to say using PWM's is not the most secure solution, the truth is that its not, at least not as how I've seen most people implement and use them.
I do use a PWM mostly because melonyogurtstrawberry still wont pass asinine password complexity calculators which look at the charset rather than the bitsize of the password. However i don't copy paste my passwords and i use a key file stored on a Token (Aladdin/Safenet eToken) to store the decryption key for the PWM DB.
On mobile phones i rather use long pass phrases which are easy enough to remember, i do add numbers and common substitutions to them tho which are not any harder to remember for me than 4 random words after couple of uses but are really not needed since even lower case alpha provides all the password complexity you can dream off if you reach 20+ chars.