Soon, your statement will be false due to Metamask Snaps feature. Basically it works like browser add-ons/extension in order to support blockchain not supported by MetaMask itself. I say soon since this feature is still on open beta.
Looks like anyone can develop and publish add-ons. The Solana wallet feature is developed by Solflare itself[1]. I wonder if this means they're confident that their native wallet won't lose customers, or is this a tactic to expand their reach? Looks like they developed this in 2022. Hopefully, it won't be plagued with fake plugins when it's officially released. CMIIW.
https://snaps.metamask.io/snap/npm/solflare-wallet/solana-snap/AFAIK you're correct. But besides fake or malicious plugin, there's also risk owner of the plugin silently changed. It already happened to some Chrome extension[1], where older owner receive deal where they receive lots of money. As for Solflare, i would bet they try to expand their reach.
[1]
https://www.theregister.com/2024/03/07/chrome_extension_changes/