Thank you for your feedback.
I agree, the "solution" I suggest, may not suit everybody. I did test out Lastpass at some point, one or two years ago, I didn't really like it, despite all the plugins to support my browsers (or perhaps, that was the very reason I didn't get comfortably with it, I like to keep the password manager far away from my browser).
But I guess more users would find Lastpass easier to deal with, compared to the KeePass solution.
I just noticed that Troy Hunt posted about his new collaboration with 1password, which allows checking if your credentials has been breached. A similar thing can be achieved with a plugin for KeePass, but again, the KeePass approach is less user friendly.
In either case, a password manager will be a great step-up, for most of us. Choosing the right one is a matter of taste and preferences, and trust.
I agree, there could be some perspective to Webauthn, though I always get a rash, when we all start relying on the same technology. Nonetheless, I will test it, once one of my favorite sites / services, offer Webauthn authentication.