if you use 4d2.org and care about warrant canarys, you should be aware that 4d2.org’s is v expired.
the website states that it is updated weekly (and in the past it has been).
the canary is more than a month out of date at this point (i am v late posting this).
i would recommend assuming that their infrastructure is fully compromised.
if you use any of their services with a mind to security or privacy,
export your data and close your accounts - do /not/ use account recovery.
(if you had attachments in vaultwarden, make sure you get those exported too)
speaking specifically on vaultwarden, while it is intended to be zero knowledge,
earlier this year researchers found ways for an adversarial server host to compromise vaults.
you can find an overview of the research here
in light of this, i have ceased using vaultwarden and instead use keepassxc.
it is a local password manager that you then need to find your own way to backup.
i wouldn’t propose this as the solution for everyone - using even bitwarden is still /far/ better
than not using a password manager at all.
for myself i am not longer interested in trusting someone else to host my password manager
and i am not interested in hosting vaultwarden for myself right now either.
if someone is going to make me feel the need to rotate nearly all my credentials, i want it to be me.