Because no editor can or should try to do everything for everyone. Plugins mean an editor can do a few things well and let others bring specific features they want later.
This vulnerability has nothing to do with password strength or security and everything to do with password reset security, i.e. email and improper handling of parameters to that reset API call.
Passkeys are interesting and potentially quite strong but they're going to have to fall back to the same old reset mechanism if you e.g. drop your passkey device (phone) into a lake.
This feels like a data issue then. Maybe one of the formerly top N instances had a weird unexpected Unicode character that caused a parse failure and it just fell out of the top N.
Kinda looks like it's designed to fit a bunch of possible plugs on the European side of things, by overlapping or offsetting the plug designs next to each other.
He wouldn't get anything, officially. He'd be off the books in some offshore military prison.