You are correct that passwords can be seen once unlocking that section, but I think the reason behind it is it’s ment for your eyes only. There are two passcode stages to go through before you see the passwords, the first to generally unlock the device so it’s Apps can be used, and if necessary by others. The second is entry to App & Web Site Passwords (even though it’s the same as the first).
I believe the idea is you never let anyone have said unlock passcode, you enter for the first stage before handing over device so others can use, but they still can’t gain access to your passwords unless you again enter the passcode (and why would you do that).
What helps is setting the duration of time-out required for said passcode to a minimum under Settings/Passcode/Require Passcode, I keep mine on “Immediately”.