I think iOS does this right. It helps you get a password from the Bitwarden app when using the browser. No browser extension with injection is required.
I'm going to stick with bitwarden. I'm not really doing anything that makes me a target. I guess someday I may regret it but it's a tradeoff of not being able to use a different password for everything and have a centralized attack point and I choose the latter. I guess it is what it is. I'm not doing anything top secret so I'm guess I'll depend on the security through obscurity that everyone rails against. Also I use 2fa wherever available.