Yes, but since this isn't some networked service I'm not as concerned about the general quality of the code. Offline attacks really have to focus on the encrypted password database. If an attacker has local access you're already owned -- they could just modify the application to do whatever they want... or keylog you, etc.
The safety of your database in a world where your keepass database is leaked due to a Dropbox attack or something is what really matters here, IMO.
Did they screw up the crypto so offline attacks are easier?