Yes but, depending on how the ecosystem is built, the amount of trust needed can be smaller or greater. Reality isn't black or white, we also have shades and colors.
Of course. I'd just rather trust many people narrowly rather than trusting a few people with everything. And the people who can push updates to password manager front ends... we're trusting them with everything. It's a situation which calls for a bit of extra diligence.