> If you are (like me) somewhat paranoid about the fact that Vaultwarden hasn't got a proper security audit on its codebase [...]

It was audited in 2024: https://www.heise.de/en/news/Password-manager-BSI-reports-cr...