Sure, but at the end of the day even if you don't update your vaultwarden server or you rely on an insecure storage sync system like dropbox, your actual vault is encrypted with a key that only you know. Even if your server is hacked or the kdbx is leaked, your passwords are safe until someone breaks AES.
not really the case: https://lemmy.ml/comment/24008121
Contrast that with hosted services, who could very easily attach their own keys to your encryption key
how would official Bitwarden be able to accomplish that? apart from this vulnerability, they can't use their servers to add their own keys.