Experience trounces review websites which these days are bought and paid for
AV Comparatives has been around for ages and conducts robust assessments. Numbers don't lie.
MWB in the wrong hands WILL damage systems. Because failing to understand the importance of bulk registry edits or similar "remediations" can leave you in a fun state.
That being said, AV is old tech. Still has a use case but signature scanning is easily avoided with little effort. It's a blunt instrument with limited scope. Those that come with ATP will at least react a little quicker, for whatever value that adds.
Behaviour/heuristic analysis has value, if it's available.
The CVE landscape has moved far beyond what it used to be and every app/site we engage with represents a risk. Especially given how modern sites are "built", (read 'pulling random chunks of code from unamanged repos')
Running apps through Virus Total can yield depressing results for many popular apps - surprises like openssl or log4j *still* being packed with even the latest versions.
The reality is those that care or are aware and will act accordingly. The vast bulk of consumers will not. At that point we're in the realm of "something is better than nothing". These consumers treat AV like it's impenetrable armour as opposed to a seatbelt. ie, the last resort you really wouldn't want to rely on to save you.
As an aside, although I loathe Kaspersky based on historical experience, chatting with their engineering team at Ignite this year was interesting. They've spent significant effort to correct the ship and had some great deep fake detection tooling. Maybe there's actual hope there.