Not necessarily. A good manager encrypts the file. Lastpass is cloud based, but there are alternatives if you want more control. The important thing is that it checks the domain matches the password and doesn't try to log into a fake site. If you do it manually you may be fooled.
RE: A new security threat